CVE-2025-22866
Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
06 feb 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Go standard library · crypto/internal/nistec¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →