PT-2026-52561 · Wolfssl+4 · Wolfssl+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The X25519 x86 64 assembly implementation fails to clear the most significant bit during the final modular reduction. This occurs because the final carry-propagation chains in the x64 and AVX2 reduction routines could overflow into the top bit, and the high limb was not masked afterward. Consequently, the computed result may not be fully reduced modulo the field prime 2^255 - 19, leaving the field element in a non-canonical form. This can lead to incorrect results from scalar multiplication and potentially the generation of an incorrect shared secret.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wolfssl
Wolfssl Jll