{"id":"CVE-2025-22866","title":"crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)","summary":"A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cvssSource":"vendor","cwe":"CWE-200","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream E4S (v.8.8)","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","cryostat 3","deployment_validation_operator","fence_agents_remediation_operator","logging_subsystem_for_red_hat_openshift","machine_deletion_remediation_operator","migration_toolkit_for_applications 7","migration_toolkit_for_containers","migration_toolkit_for_virtualization","multiarch_tuning_operator","multicluster_engine_for_kubernetes","nbde_tang_server","network_observability_operator","node_healthcheck_operator","node_maintenance_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_pipelines","openshift_run_once_duration_override_operator","openshift_secondary_scheduler_operator","openshift_serverless","openshift_service_mesh 2","openshift_service_mesh 3","openshift_source_to_image_s2i","power_monitoring_for_red_hat_openshift","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","ansible_automation_platform 1.2","ansible_automation_platform 2","ceph_storage 5","ceph_storage 6","ceph_storage 8","connectivity_link 1","enterprise_linux 10","enterprise_linux 7","enterprise_linux 8"],"patched":["8base_openshift_serverless_1_36","rhossm_2_5_for_rhel 8","advanced_cluster_management_for_kubernetes_2_11_for_rhel 9","advanced_cluster_management_for_kubernetes_2_12_for_rhel 9","advanced_cluster_management_for_kubernetes_2_13_for_rhel 9","ceph_storage_7_1_tools","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_v_9","enterprise_linux_codeready_linux_builder_v_9","hawtio_hawtio 4.2.0","openshift_distributed_tracing 3.5.3","multicluster_engine_for_kubernetes 2.11","multicluster_engine_for_kubernetes 2.1","multicluster_engine_for_kubernetes 2.6","multicluster_engine_for_kubernetes 2.8","multicluster_engine_for_kubernetes 2.9"],"published":"2025-02-06","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:19:13+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22866.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22866.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-22866"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2344219"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-22866"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22866"},{"url":"https://go.dev/cl/643735"},{"url":"https://go.dev/issue/71383"},{"url":"https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k"},{"url":"https://pkg.go.dev/vuln/GO-2025-3447"},{"url":"https://access.redhat.com/errata/RHSA-2025:8670"},{"url":"https://access.redhat.com/errata/RHSA-2025:3922"},{"url":"https://access.redhat.com/errata/RHSA-2025:4810"},{"url":"https://access.redhat.com/errata/RHSA-2025:4666"},{"url":"https://access.redhat.com/errata/RHEA-2025:3039"},{"url":"https://access.redhat.com/errata/RHSA-2025:16113"},{"url":"https://access.redhat.com/errata/RHSA-2025:4667"},{"url":"https://access.redhat.com/errata/RHSA-2025:7466"},{"url":"https://access.redhat.com/errata/RHSA-2026:67148"},{"url":"https://access.redhat.com/errata/RHSA-2026:69235"},{"url":"https://access.redhat.com/errata/RHSA-2026:4693"},{"url":"https://access.redhat.com/errata/RHSA-2026:68504"},{"url":"https://access.redhat.com/errata/RHSA-2025:3773"},{"url":"https://access.redhat.com/errata/RHSA-2025:7326"},{"url":"https://access.redhat.com/errata/RHSA-2025:8761"},{"url":"https://access.redhat.com/errata/RHSA-2025:2789"},{"url":"https://access.redhat.com/errata/RHSA-2026:57194"},{"url":"https://access.redhat.com/errata/RHSA-2026:59556"},{"url":"https://access.redhat.com/errata/RHSA-2026:59557"},{"url":"https://access.redhat.com/errata/RHSA-2026:54432"},{"url":"https://access.redhat.com/errata/RHSA-2026:59579"},{"url":"https://access.redhat.com/errata/RHSA-2026:59558"},{"url":"https://access.redhat.com/errata/RHSA-2026:59559"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0029,"epssPercentile":0.21741,"aliases":["GO-2025-3447","BIT-golang-2025-22866"],"ecosystem":"go","ingestedAt":"2026-08-18T12:28:10.754Z","slug":"CVE-2025-22866","body":"## Overview\n\nA flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Considering how this function is used, this leakage is likely insufficient to recover the private key when P-256 is used in any well-known protocols.\n\n## Vendor advisories\n\n- **RHSA-2025:8670** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2025-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2025:8670)\n- **RHSA-2025:3922** · Red Hat · fixed in: RHOSSM 2.5 for RHEL 8 · released 2025-04-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:3922)\n- **RHSA-2025:4810** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 · released 2025-05-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:4810)\n- **RHSA-2025:4666** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 · released 2025-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:4666)\n- **RHEA-2025:3039** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 · released 2025-03-19 · [advisory](https://access.redhat.com/errata/RHEA-2025:3039)\n- **RHSA-2025:16113** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 · released 2025-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:16113)\n- **RHSA-2025:4667** · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2025-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:4667)\n- **RHSA-2025:7466** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2025-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:7466)\n- **RHSA-2026:67148** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67148)\n- **RHSA-2026:69235** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69235)\n- **RHSA-2026:4693** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-03-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:4693)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Cryostat 3, Deployment Validation Operator, … · no fix planned: OpenShift Secondary Scheduler Operator, OpenShift Service Mesh 3, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Security 4, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-22866.json)\n- **RHSA-2026:68504** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68504)\n- **RHSA-2025:3773** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2025-04-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:3773)\n- **RHSA-2025:7326** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2025-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:7326)\n\n**crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec** — rated Moderate by Red Hat. Released 2025-02-06, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Cryostat 3\n- Deployment Validation Operator\n- Fence Agents Remediation Operator\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 7\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- NBDE Tang Server\n- Network Observability Operator\n- Node HealthCheck Operator\n- Node Maintenance Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Pipelines\n- OpenShift Run Once Duration Override Operator\n- OpenShift Secondary Scheduler Operator\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- OpenShift Source-to-Image (S2I)\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ansible Automation Platform 1.2\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 8\n- Red Hat Connectivity Link 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n\nFixed:\n\n- 8Base-Openshift-Serverless-1.36\n- RHOSSM 2.5 for RHEL 8\n- Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9\n- Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9\n- Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9\n- Red Hat Ceph Storage 7.1 Tools\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)\n- HawtIO HawtIO 4.2.0\n- Red Hat OpenShift distributed tracing 3.5.3\n- multicluster engine for Kubernetes 2.11\n- multicluster engine for Kubernetes 2.1\n- multicluster engine for Kubernetes 2.6\n- multicluster engine for Kubernetes 2.8\n- multicluster engine for Kubernetes 2.9\n\nNo fix planned:\n\n- OpenShift Secondary Scheduler Operator\n- OpenShift Service Mesh 3\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Ceph Storage 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift on AWS\n- Cryostat 3\n- Fence Agents Remediation Operator\n- Logging Subsystem for Red Hat OpenShift\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 7\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Node HealthCheck Operator\n- Node Maintenance Operator\n- OpenShift API for Data Protection\n- OpenShift Service Mesh 2\n- OpenShift Source-to-Image (S2I)\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux 8\n- Red Hat Openshift Sandboxed Containers\n- Red Hat Quay 3\n- Red Hat Service Interconnect 1\n- Self Node Remediation Operator\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- NBDE Tang Server\n\nNot affected:\n\n- 8Base-Openshift-Serverless-1.36\n- RHOSSM 2.5 for RHEL 8\n- Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9\n- Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9\n- Red Hat OpenShift distributed tracing 3.5.3\n- Custom Metric Autoscaler operator for Red Hat Openshift\n- Kube Descheduler Operator\n- Logical Volume Manager Storage\n- multicluster engine for Kubernetes 2.11\n- multicluster engine for Kubernetes 2.1\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:8670\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:3922\nTo learn more about Submariner, see https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/networking/networking#submariner. https://access.redhat.com/errata/RHSA-2025:4810\n\n## Package advisory (CVE-2025-22866)\n\nAffected packages:\n\n- `stdlib >= 1.24.0-0, < 1.24.0-rc.3`\n\nPatched in:\n\n- `stdlib 1.24.0-rc.3`\n\nSource: https://osv.dev/vulnerability/GO-2025-3447","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":4794,"id":"CVE-2025-22866","ts":1788887207115,"field":"cvss","old":null,"new":"5.3"},{"seq":4793,"id":"CVE-2025-22866","ts":1788887207115,"field":"severity","old":"none","new":"medium"},{"seq":3677,"id":"CVE-2025-22866","ts":1788886324156,"field":"cvss","old":"5.3","new":null},{"seq":3676,"id":"CVE-2025-22866","ts":1788886324156,"field":"severity","old":"medium","new":"none"},{"seq":3171,"id":"CVE-2025-22866","ts":1788883133194,"field":"cvss","old":null,"new":"5.3"},{"seq":3170,"id":"CVE-2025-22866","ts":1788883133194,"field":"severity","old":"none","new":"medium"}]}