The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.
References
| Link | Resource |
|---|---|
| https://crates.io/crates/curve25519-dalek | Product |
| https://github.com/dalek-cryptography/curve25519-dalek/pull/659 | Issue Tracking Patch |
| https://rustsec.org/advisories/RUSTSEC-2024-0344.html | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-07-27 20:15
Updated : 2025-08-07 14:58
NVD link : CVE-2024-58262
Mitre link : CVE-2024-58262
CVE.ORG link : CVE-2024-58262
JSON object : View
Products Affected
dalek
- curve25519-dalek
CWE
CWE-733
Compiler Optimization Removal or Modification of Security-critical Code
