First published: Mon Jan 27 2025(Updated: )
In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
illumos | =2024-02-15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26317 has a moderate severity level due to its potential to allow man-in-the-middle attacks.
To mitigate CVE-2024-26317, upgrade to the latest version of illumos-gate that addresses this elliptic curve algorithm issue.
CVE-2024-26317 affects illumos-gate version 2024-02-15.
CVE-2024-26317 can be exploited by a man-in-the-middle attacker to interfere with secure communications.
CVE-2024-26317 involves an error in the elliptic curve point addition algorithm leading to incorrect results during calculations.