U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-1544

Change History

New CVE Received from wolfSSL Inc. 8/27/2024 3:15:16 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Generating the ECDSA nonce k samples a random number r and then 
truncates this randomness with a modular reduction mod n where n is the 
order of the elliptic curve. Meaning k = r mod n. The division used 
during the reduction estimates a factor q_e by dividing the upper two 
digits (a digit having e.g. a size of 8 byte) of r by the upper digit of 
n and then decrements q_e in a loop until it has the correct size. 
Observing the number of times q_e is decremented through a control-flow 
revealing side-channel reveals a bias in the most significant bits of 
k. Depending on the curve this is either a negligible bias or a 
significant bias large enough to reconstruct k with lattice reduction 
methods. For SECP160R1, e.g., we find a bias of 15 bits.
Added CVSS V3.1

								
							
							
						
wolfSSL Inc. AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
wolfSSL Inc. CWE-203
Added Reference

								
							
							
						
wolfSSL Inc. https://github.com/wolfSSL/wolfssl/releases/tag/v5.7.2-stable [No types assigned]