Impact
The vulnerability arises in the mirage-crypto-ec library prior to version 2.3.0 when a compressed elliptic-curve public key is processed. An out-of-bounds memory read can occur if the key data lies beyond the allocated buffer, potentially exposing arbitrary memory contents. The weakness is classified as CWE-125, a classic out-of-bounds read, which can lead to information disclosure or application crashes.
Affected Systems
OCaml mirage-crypto-ec, any version before 2.3.0. Any program that uses the library to parse compressed EC points is affected.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate impact. EPSS is not available, so the likelihood of exploitation is unclear. The vulnerability is not listed in CISA KEV. Without a clear remote exploitation path, the attacker must supply a crafted EC point to trigger the read, typically by sending crafted data to a service that processes EC keys. The primary consequence is information disclosure or denial of service, rather than remote code execution.
OpenCVE Enrichment