CVE-2023-26557

io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is in crypto/paillier/paillier.go. (bnb-chain/tss-lib and thorchain/tss are also affected.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:iofinnet:tss-lib:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-04-21 18:15

Updated : 2023-11-07 04:09


NVD link : CVE-2023-26557

Mitre link : CVE-2023-26557

CVE.ORG link : CVE-2023-26557


JSON object : View

Products Affected

iofinnet

  • tss-lib
CWE
CWE-203

Observable Discrepancy