Vulnerability record · CVE-2024-50382 · published 23 October 2024
CVE-2024-50382: Botan project botan observable discrepancy vulnerability
Botan Project · Botan
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.
Description
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://arxiv.org/pdf/2410.13489 | ExploitTechnical DescriptionThird Party Advisory |
| https://github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957 | Patch |
| https://github.com/randombit/botan/compare/3.5.0...3.6.0 | Product |
| https://news.ycombinator.com/item?id=41887153 | Issue Tracking |
Track CVE-2024-50382 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-50382), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.