/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pq7j-mjwx-crc2

Published

Last updated

https://images.chainguard.dev/security/CGA-pq7j-mjwx-crc2
Package

kyverno-fips-1.14

Repository

Chainguard

Latest Update
Fixed
Fixed Version

1.14.2-r2

Aliases
  • GHSA-2x5j-vhc8-9cwm

Severity

Unknown

Summary

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

Description

Impact

The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.

Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.

Patches

Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.

We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

References

Updates

Status

Fixed

Fixed version

1.14.2-r2

Status

Affected

Impact

Unable to use govulncheck to triage this advisory because the vulnerability was not found in the Go vuln DB. Treating as a true positive since we can't confirm this is a false positive.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing