CVE-2017-8932
published 2017-07-06CVE-2017-8932: A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.23%
80.7th percentile
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| golang | go | <= 1.7.5 | — |
| golang | go | — | — |
| golang | go | — | — |
| novell | suse_package_hub_for_suse_linux_enterprise | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang: Elliptic curves carry propagation issue in x86-64 P-256
vendor_redhat·2017-05-23·CVSS 5.9
CVE-2017-8932 [MEDIUM] CWE-682 golang: Elliptic curves carry propagation issue in x86-64 P-256
golang: Elliptic curves carry propagation issue in x86-64 P-256
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
A carry propagation flaw was found in the implementation of the P-256 elliptic curve in golang. An attacker could possibly use this flaw to extract private keys when static ECDH was used.
Package: golang (Red Hat OpenShift Enterprise 3) - Under investigation
OSV
Incorrect computation for P-256 curves in crypto/elliptic
osv·2022-07-01
CVE-2017-8932 Incorrect computation for P-256 curves in crypto/elliptic
Incorrect computation for P-256 curves in crypto/elliptic
The ScalarMult implementation of curve P-256 for amd64 architectures generates incorrect results for certain specific input points. An adaptive attack can progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
GHSA
GHSA-25hf-x7c8-5f3h: A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1
ghsa_unreviewed·2022-05-13
CVE-2017-8932 [MEDIUM] CWE-682 GHSA-25hf-x7c8-5f3h: A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
OSV
CVE-2017-8932: A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1
osv·2017-07-06·CVSS 5.9
CVE-2017-8932 [MEDIUM] CVE-2017-8932: A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [fedora-all]
bugzilla·2017-05-24·CVSS 5.9
CVE-2017-8932 [MEDIUM] CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [fedora-all]
CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [epel-6]
bugzilla·2017-05-24·CVSS 5.9
CVE-2017-8932 [MEDIUM] CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [epel-6]
CVE-2017-8932 golang: Elliptic curvers carry propagation issue in x86-64 P-256 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for
Bugzilla
CVE-2017-8932 golang: Elliptic curves carry propagation issue in x86-64 P-256
bugzilla·2017-05-24·CVSS 5.9
CVE-2017-8932 [MEDIUM] CVE-2017-8932 golang: Elliptic curves carry propagation issue in x86-64 P-256
CVE-2017-8932 golang: Elliptic curves carry propagation issue in x86-64 P-256
A carry propagation issue was found in the P-256 implementation for x86-64 in golang.
Upstream issue:
https://github.com/golang/go/issues/20040
Upstream patch:
https://golang.org/cl/41070
Discussion:
Created golang tracking bugs for this issue:
Affects: epel-6 [bug 1455190]
Affects: fedora-all [bug 1455191]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1859 https://access.redhat.com/errata/RHSA-2017:1859
http://lists.opensuse.org/opensuse-updates/2017-06/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2017-06/msg00080.htmlhttps://access.redhat.com/errata/RHSA-2017:1859https://bugzilla.redhat.com/show_bug.cgi?id=1455191https://github.com/golang/go/commit/9294fa2749ffee7edbbb817a0ef9fe633136fa9chttps://github.com/golang/go/issues/20040https://go-review.googlesource.com/c/41070/https://groups.google.com/d/msg/golang-announce/B5ww0iFt1_Q/TgUFJV14BgAJhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZH4T47ROLZ6YEZBDVXVS2KISTDMXAPS/http://lists.opensuse.org/opensuse-updates/2017-06/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2017-06/msg00080.htmlhttps://access.redhat.com/errata/RHSA-2017:1859https://bugzilla.redhat.com/show_bug.cgi?id=1455191https://github.com/golang/go/commit/9294fa2749ffee7edbbb817a0ef9fe633136fa9chttps://github.com/golang/go/issues/20040https://go-review.googlesource.com/c/41070/https://groups.google.com/d/msg/golang-announce/B5ww0iFt1_Q/TgUFJV14BgAJhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZH4T47ROLZ6YEZBDVXVS2KISTDMXAPS/
2017-07-06
Published