CVE-2025-22866

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

Open
NONE (0.0)
  • T

    Tim Bastin detected CVE-2025-22866

  • T

    Tim Bastin fixed CVE-2025-22866

  • T

    Tim Bastin detected CVE-2025-22866

  • logo

    System removed scanner:

  • logo

    System removed scanner:

  • logo

    System removed scanner:

  • T

    Tim Bastin fixed CVE-2025-22866

  • logo

    System detected CVE-2025-22866

  • T

    Tim Bastin fixed CVE-2025-22866

  • logo

    System detected CVE-2025-22866

Add a comment

Mark as False Positive
Last calculated at:

Affected component

Logo von golang stdlib

Installed version:
1.21.8
Fixed in:
v1.22.12

Quick Fix

Update all Dependencies
Update only stdlib
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 667098114b5ef45c7830e7aa599604fa65eb818f