A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
History

Wed, 06 Aug 2025 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Title Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results
First Time appeared Redhat
Redhat acm
Redhat advanced Cluster Security
Redhat ceph Storage
Redhat container Native Virtualization
Redhat devworkspace
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat multicluster Globalhub
Redhat openshift
Redhat openshift Ai
Redhat openshift Builds
Redhat openshift Custom Metrics Autoscaler
Redhat openshift Gitops
Redhat openshift Pipelines
Redhat openstack
Redhat rhdh
Redhat serverless
Redhat service Mesh
Redhat trusted Application Pipeline
Redhat trusted Artifact Signer
Redhat trusted Profile Analyzer
Redhat windows Machine Config
Weaknesses CWE-347
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:advanced_cluster_security:4
cpe:/a:redhat:ceph_storage:5
cpe:/a:redhat:ceph_storage:6
cpe:/a:redhat:ceph_storage:8
cpe:/a:redhat:container_native_virtualization:4
cpe:/a:redhat:devworkspace
cpe:/a:redhat:enterprise_linux_ai:1
cpe:/a:redhat:multicluster_globalhub
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_builds:1
cpe:/a:redhat:openshift_custom_metrics_autoscaler:2
cpe:/a:redhat:openshift_gitops:1
cpe:/a:redhat:openshift_pipelines:1
cpe:/a:redhat:openstack:16.2
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:rhdh:1
cpe:/a:redhat:serverless:1
cpe:/a:redhat:service_mesh:3
cpe:/a:redhat:trusted_application_pipeline:1
cpe:/a:redhat:trusted_artifact_signer:1
cpe:/a:redhat:trusted_profile_analyzer:1
cpe:/a:redhat:windows_machine_config
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat acm
Redhat advanced Cluster Security
Redhat ceph Storage
Redhat container Native Virtualization
Redhat devworkspace
Redhat enterprise Linux
Redhat enterprise Linux Ai
Redhat multicluster Globalhub
Redhat openshift
Redhat openshift Ai
Redhat openshift Builds
Redhat openshift Custom Metrics Autoscaler
Redhat openshift Gitops
Redhat openshift Pipelines
Redhat openstack
Redhat rhdh
Redhat serverless
Redhat service Mesh
Redhat trusted Application Pipeline
Redhat trusted Artifact Signer
Redhat trusted Profile Analyzer
Redhat windows Machine Config
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-08-06T08:48:17.946Z

Updated: 2025-08-06T09:09:23.503Z

Reserved: 2025-08-04T14:05:14.993Z

Link: CVE-2025-8556

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-08-06T09:15:28.173

Modified: 2025-08-06T09:15:28.173

Link: CVE-2025-8556

cve-icon Redhat

No data.