Elliptic Curve Point Addition Vulnerability in Illumos-Gate Software
CVE-2024-26317

6.1MEDIUM

Key Information:

Vendor

Illumos

Vendor
CVE Published:
27 January 2025

What is CVE-2024-26317?

A flaw has been detected in the elliptic curve point addition algorithm within the illumos-gate software. Specifically, an incorrect handling of mixed Jacobian-affine coordinates leads to a situation where the algorithm produces a POINT_AT_INFINITY result under certain conditions. This miscalculation allows a man-in-the-middle attacker to potentially disrupt secure connections, resulting in the calculation of an incorrect shared secret. Such vulnerabilities could jeopardize sensitive communications, emphasizing the importance of timely updates and mitigation measures.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.