Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which present…
低危 CVSS 3.7
摘要
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02 Patch
- https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb Patch
- https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c Patch
- https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2 Patch
- https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070 Patch
- https://openssl-library.org/news/secadv/20260609.txt Vendor Advisory
时间线
- nvd_ingest NVD