Incorrect calculation in Go programming language - CVE-2023-24532

 

Incorrect calculation in Go programming language - CVE-2023-24532

Published: March 13, 2023


Vulnerability identifier: #VU73264
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24532
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars.


Affected software

Go programming language
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Fedora
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Containers Module
Development Tools Module
openSUSE Leap
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Db2 Rest
ObjectScale
Dell EMC Streaming Data Platform
DB2 Data Management Console
IBM Cloud Pak for Watson AIOps
IBM Watson Machine Learning Accelerator
Storage Protect Server
Storage Protect Plus Container Agent
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
AdGuard Home
Event Streams
Cloud Pak for Data
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Run Once Duration Override Operator for Red Hat OpenShift
Service Telemetry Framework
IBM Spectrum Copy Data Management
IBM Watson Assistant for IBM Cloud Pak for Data
Red Hat OpenStack
Operations Dashboard
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
Data Replication on Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Spectrum Protect Plus
IBM Observability with Instana
Migration Toolkit for Containers
QRadar Suite
golang
go1.19-doc
go1.19
go1.19-race
go1.20
go1.20-race
go1.20-doc
container-suseconnect
watsonx.data
IBM Cloud Pak System

How to mitigate CVE-2023-24532

Install updates from vendor's website.

Go programming language - addressed in versions 1.19.7, 1.20.2
AdGuard Home - addressed in versions 0.107.26, 0.108.0-b.30
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.2
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
OpenShift API for Data Protection (OADP) - update to 1.1.6
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - update to 1.7.12
QRadar Suite - update to 1.10.18.0
IBM Spectrum Copy Data Management - update to 2.2.20.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
Event Streams - update to 11.1.6
Red Hat OpenStack - update to 16.2.5
Operations Dashboard - update to 2022.2.1-10-lts
Db2 Rest - update to 1.0.0.266
ObjectScale - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
golang - addressed in versions 1.18.6-1.43, 1.19.8-1
go1.19-doc - update to 1.19.7-150000.1.23.1
go1.19 - update to 1.19.7-150000.1.23.1
go1.19-race - update to 1.19.7-150000.1.23.1
golang - update to 1.19.13-1.el7
go1.20 - update to 1.20.2-150000.1.5.1
go1.20-race - update to 1.20.2-150000.1.5.1
go1.20-doc - update to 1.20.2-150000.1.5.1
watsonx.data - update to 2.0.1
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
container-suseconnect - update to 2.4.0-150000.4.24.1
DB2 Data Management Console - update to 3.1.13
IBM Cloud Transformation Advisor - update to 3.7.0
IBM Cloud Pak for Watson AIOps - update to 4.1.2
IBM Watson Machine Learning Accelerator - addressed in versions 4.2.0, 4.8.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
Data Replication on Cloud Pak for Data - update to 4.7.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7.1
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
IBM Cloud Pak for Data Scheduling - update to 4.8.0
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0
Red Hat Migration Toolkit for Applications - update to 6.2.0
Storage Protect Server - update to 8.1.19
Storage Protect Plus Container Agent - update to 10.1.12.6
IBM Spectrum Protect Plus - update to 10.1.15
Dell PowerProtect Cyber Recovery - update to 19.14.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.4, 23.0.5
IBM Observability with Instana - update to 281
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-8, 2022.2.1-9, 2022.4.1-4

External References

Related Security Bulletins