Improper random reading in CIRCL
CVE-2023-1732
5.3MEDIUM
What is CVE-2023-1732?
The implementation of cryptographic components Kyber and FrodoKEM in Cloudflare products contains a flaw in randomness sampling for shared secrets. A failure to verify whether the crypto/rand.Read() function returns an error can lead to scenarios where predictable shared secrets are generated, particularly under rare deployment circumstances. Additionally, components like tkn20 and blindrsa fail to adequately check if sufficient randomness is provided by user-supplied sources. This oversight may compromise the integrity of the plaintext, as weakened blinding in blindrsa no longer assures robust security.
Affected Version(s)
CIRCL Go 0
