CVE List

CVE-2022-37454

Severe 9.8

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Published October 21, 2022.

Affected software

Get alerts for Extended Keccak Code Package Project Extended Keccak Code Package

Reference links