Multiplication of certain unreduced P-256 scalars produce incorrect results.
There are no protocols known at this time that can be attacked due to this.
{ "url": "https://pkg.go.dev/vuln/GO-2023-1595", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "P256Point.ScalarBaseMult", "P256Point.ScalarMult", "p256OrdInverse" ], "goarch": [ "amd64", "arm64", "ppc64le", "s390x" ], "path": "filippo.io/nistec" } ] }