Elliptic Curve Point Addition Vulnerability in Illumos-Gate Software
CVE-2024-26317
6.1MEDIUM
What is CVE-2024-26317?
A flaw has been detected in the elliptic curve point addition algorithm within the illumos-gate software. Specifically, an incorrect handling of mixed Jacobian-affine coordinates leads to a situation where the algorithm produces a POINT_AT_INFINITY result under certain conditions. This miscalculation allows a man-in-the-middle attacker to potentially disrupt secure connections, resulting in the calculation of an incorrect shared secret. Such vulnerabilities could jeopardize sensitive communications, emphasizing the importance of timely updates and mitigation measures.
