Impact
A flaw in mirage-crypto’s decrypt functions causes the decrypted plaintext to be written into a caller‑supplied buffer before the authentication tag is checked. When the tag is forged, the functions return false, yet the buffer still contains the full plaintext. This results in inadvertent information disclosure, exposing sensitive data without proper authentication, and exemplifies CWE‑347.
Affected Systems
The vulnerability affects the mirage-crypto library for OCaml. All releases before version 2.2.0 are impacted, including the specific AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply forged ciphertext and tags, which can be achieved locally if the library is used in an untrusted context or remotely if the decryption routine is exposed through an application interface. The attack ultimately retrieves plaintext data, compromising confidentiality but not privilege levels or availability.
OpenCVE Enrichment