CVE-2024-1394High· 7.5▾ TwilightMemory leaks in code encrypting and verifying RSA payloads
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
Using crafted public RSA keys which are not compliant with SP 800-56B can cause a small memory leak when encrypting and verifying payloads.
An attacker can leverage this flaw to gradually erode available memory to the point where the host crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
github.com/golang-fips/go <= 1.22.1github.com/golang-fips/openssl/v2 < 2.0.1github.com/microsoft/go-crypto-openssl <= 0.2.8github.com/microsoft/go-crypto-openssl/openssl < 0.2.9Upgrade to a patched release:
github.com/golang-fips/openssl/v2 2.0.1github.com/microsoft/go-crypto-openssl/openssl 0.2.9Connected by shared product, vendor, weakness, or advisory.