CVE-2024-58262 describes a vulnerability in the curve25519-dalek Rust crate prior to version 4.1.3, where a critical constant-time operation on elliptic curve scalars is inadvertently optimized away by LLVM. This flaw, rated Medium severity (CVSS 5.1), has a high impact on confidentiality due to the potential for side-channel attacks, though it requires local access and high attack complexity. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.3CPE matchmatch criteria | cpe:2.3:a:dalek:curve25519-dalek:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.