Description
An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1840-1 | golang-go.crypto security update |
Debian DLA |
DLA-2402-1 | golang-go.crypto security update |
Debian DLA |
DLA-2442-1 | obfs4proxy security update |
Debian DLA |
DLA-2454-1 | rclone security update |
Debian DLA |
DLA-2527-1 | snapd security update |
Debian DLA |
DLA-3455-1 | golang-go.crypto security update |
EUVD |
EUVD-2022-5096 | An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications. |
Github GHSA |
GHSA-r5c5-pr8j-pfp7 | golang.org/x/crypto/salsa20/salsa uses insufficiently random values |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:03:32.886Z
Reserved: 2019-05-09T00:00:00.000Z
Link: CVE-2019-11840
No data.
Status : Modified
Published: 2019-05-09T16:29:00.607
Modified: 2024-11-21T04:21:52.383
Link: CVE-2019-11840
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA