CVE-2024-50383: Medium severity botan vulnerability

Published Oct 23, 2024
·
Updated

Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)

Affected Software

2 affected components
Botan Botan<3.6.0
Botan Project Botan<3.6.0

Event History

Oct 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-50383?

CVE-2024-50383 is considered to have a medium severity level due to its potential impact on cryptographic operations.

2

How do I fix CVE-2024-50383?

To fix CVE-2024-50383, upgrade Botan to version 3.6.0 or later, which addresses the vulnerability.

3

Which versions of Botan are affected by CVE-2024-50383?

CVE-2024-50383 affects all versions of Botan prior to 3.6.0.

4

What specific operations are impacted by CVE-2024-50383?

CVE-2024-50383 impacts secret-dependent operations in the donna128 implementation used in Chacha-Poly1305 and x25519.

5

What compilers are known to trigger CVE-2024-50383?

GCC versions, specifically 11.3.0 with -O2 on MIPS and x86-i386 architectures, are known to trigger CVE-2024-50383.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203