CVE-2023-26557

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is in crypto/paillier/paillier.go. (bnb-chain/tss-lib and thorchain/tss are also affected.)

Threshold Signature Scheme for ECDSA/EdDSA
GitHubGitHub
7
Threshold Signature Scheme, for ECDSA and EDDSA
GitHubGitHub
1.02K