Improper random reading in CIRCL
CVE-2023-1732
What is CVE-2023-1732?
The implementation of cryptographic components Kyber and FrodoKEM in Cloudflare products contains a flaw in randomness sampling for shared secrets. A failure to verify whether the crypto/rand.Read() function returns an error can lead to scenarios where predictable shared secrets are generated, particularly under rare deployment circumstances. Additionally, components like tkn20 and blindrsa fail to adequately check if sufficient randomness is provided by user-supplied sources. This oversight may compromise the integrity of the plaintext, as weakened blinding in blindrsa no longer assures robust security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CIRCL Go 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
