Medium severity5.9NVD Advisory· Published Oct 23, 2024· Updated Jun 17, 2026
CVE-2024-50382
CVE-2024-50382
Description
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*range: <3.6.0
- (no CPE)range: <3.6.0
- Botan/Botandescription
- osv-coords5 versionspkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/Botan&distro=openSUSE%20Tumbleweedpkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP5pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP6
< 2.19.5-bp156.3.6.1+ 4 more
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 3.6.0-1.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
Patches
Vulnerability mechanics
References
4- github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957nvdPatch
- arxiv.org/pdf/2410.13489nvdExploitTechnical DescriptionThird Party Advisory
- github.com/randombit/botan/compare/3.5.0...3.6.0nvdProduct
- news.ycombinator.com/itemnvdIssue Tracking
News mentions
0No linked articles in our index yet.