A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange. | |
Title | Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results | |
First Time appeared |
Redhat
Redhat acm Redhat advanced Cluster Security Redhat ceph Storage Redhat container Native Virtualization Redhat devworkspace Redhat enterprise Linux Redhat enterprise Linux Ai Redhat multicluster Globalhub Redhat openshift Redhat openshift Ai Redhat openshift Builds Redhat openshift Custom Metrics Autoscaler Redhat openshift Gitops Redhat openshift Pipelines Redhat openstack Redhat rhdh Redhat serverless Redhat service Mesh Redhat trusted Application Pipeline Redhat trusted Artifact Signer Redhat trusted Profile Analyzer Redhat windows Machine Config |
|
Weaknesses | CWE-347 | |
CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:advanced_cluster_security:4 cpe:/a:redhat:ceph_storage:5 cpe:/a:redhat:ceph_storage:6 cpe:/a:redhat:ceph_storage:8 cpe:/a:redhat:container_native_virtualization:4 cpe:/a:redhat:devworkspace cpe:/a:redhat:enterprise_linux_ai:1 cpe:/a:redhat:multicluster_globalhub cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_ai cpe:/a:redhat:openshift_builds:1 cpe:/a:redhat:openshift_custom_metrics_autoscaler:2 cpe:/a:redhat:openshift_gitops:1 cpe:/a:redhat:openshift_pipelines:1 cpe:/a:redhat:openstack:16.2 cpe:/a:redhat:openstack:17.1 cpe:/a:redhat:rhdh:1 cpe:/a:redhat:serverless:1 cpe:/a:redhat:service_mesh:3 cpe:/a:redhat:trusted_application_pipeline:1 cpe:/a:redhat:trusted_artifact_signer:1 cpe:/a:redhat:trusted_profile_analyzer:1 cpe:/a:redhat:windows_machine_config cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat acm Redhat advanced Cluster Security Redhat ceph Storage Redhat container Native Virtualization Redhat devworkspace Redhat enterprise Linux Redhat enterprise Linux Ai Redhat multicluster Globalhub Redhat openshift Redhat openshift Ai Redhat openshift Builds Redhat openshift Custom Metrics Autoscaler Redhat openshift Gitops Redhat openshift Pipelines Redhat openstack Redhat rhdh Redhat serverless Redhat service Mesh Redhat trusted Application Pipeline Redhat trusted Artifact Signer Redhat trusted Profile Analyzer Redhat windows Machine Config |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-08-06T08:48:17.946Z
Updated: 2025-08-06T09:09:23.503Z
Reserved: 2025-08-04T14:05:14.993Z
Link: CVE-2025-8556

No data.

Status : Received
Published: 2025-08-06T09:15:28.173
Modified: 2025-08-06T09:15:28.173
Link: CVE-2025-8556

No data.