CVE-2024-58262

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dalek:curve25519-dalek:*:*:*:*:*:rust:*:*

History

07 Aug 2025, 14:58

Type Values Removed Values Added
First Time Dalek curve25519-dalek
Dalek
CPE cpe:2.3:a:dalek:curve25519-dalek:*:*:*:*:*:rust:*:*
References () https://crates.io/crates/curve25519-dalek - () https://crates.io/crates/curve25519-dalek - Product
References () https://github.com/dalek-cryptography/curve25519-dalek/pull/659 - () https://github.com/dalek-cryptography/curve25519-dalek/pull/659 - Issue Tracking, Patch
References () https://rustsec.org/advisories/RUSTSEC-2024-0344.html - () https://rustsec.org/advisories/RUSTSEC-2024-0344.html - Third Party Advisory

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) El paquete curve25519-dalek para Rust anterior a 4.1.3 tiene una operación de tiempo constante en escalares de curva elíptica que es eliminada por LLVM.

27 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-27 20:15

Updated : 2025-08-07 14:58


NVD link : CVE-2024-58262

Mitre link : CVE-2024-58262

CVE.ORG link : CVE-2024-58262


JSON object : View

Products Affected

dalek

  • curve25519-dalek
CWE
CWE-733

Compiler Optimization Removal or Modification of Security-critical Code