Medium severity5.9NVD Advisory· Published Oct 23, 2024· Updated Jun 17, 2026
CVE-2024-50383
CVE-2024-50383
Description
Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:botan_project:botan:*:*:*:*:*:*:*:*range: <3.6.0
- (no CPE)range: <3.6.0
- Botan/Botandescription
- osv-coords4 versionspkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/Botan&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP5pkg:rpm/suse/Botan&distro=SUSE%20Package%20Hub%2015%20SP6
< 2.19.5-bp156.3.6.1+ 3 more
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
- (no CPE)range: < 2.19.5-bp156.3.6.1
Patches
Vulnerability mechanics
References
4- github.com/randombit/botan/commit/53b0cfde580e86b03d0d27a488b6c134f662e957nvdPatch
- arxiv.org/pdf/2410.13489nvdExploitTechnical DescriptionThird Party Advisory
- github.com/randombit/botan/compare/3.5.0...3.6.0nvdProduct
- news.ycombinator.com/itemnvdIssue Tracking
News mentions
0No linked articles in our index yet.