CVE-2025-8556
Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
circlRed Hat · Builds for Red Hat OpenShiftRed Hat · Custom Metric Autoscaler operator for Red Hat OpenshiftRed Hat · Multicluster Global HubRed Hat · OpenShift PipelinesRed Hat · OpenShift ServerlessRed Hat · OpenShift Service Mesh 3Red Hat · Red Hat Advanced Cluster Management for Kubernetes 2Red Hat · Red Hat Advanced Cluster Security 4Red Hat · Red Hat Ceph Storage 5Red Hat · Red Hat Ceph Storage 6Red Hat · Red Hat Ceph Storage 8Red Hat · Red Hat Developer HubRed Hat · Red Hat Edge Manager previewRed Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux AI (RHEL AI)Red Hat · Red Hat OpenShift AI (RHOAI)Red Hat · Red Hat OpenShift Container Platform 4Red Hat · Red Hat OpenShift Dev Workspaces OperatorRed Hat · Red Hat OpenShift for Windows ContainersRed Hat · Red Hat OpenShift GitOpsRed Hat · Red Hat OpenShift Virtualization 4Red Hat · Red Hat OpenStack Platform 16.2Red Hat · Red Hat OpenStack Platform 17.1Red Hat · Red Hat Trusted Application PipelineRed Hat · Red Hat Trusted Artifact SignerRed Hat · Red Hat Trusted Profile Analyzer¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/security/cve/CVE-2025-8556https://bugzilla.redhat.com/show_bug.cgi?id=2371624https://github.com/cloudflare/circlhttps://github.com/cloudflare/circl/security/advisories/GHSA-2x5j-vhc8-9cwmhttps://github.com/cloudflare/circl/tree/v1.6.1https://news.ycombinator.com/item?id=45669593https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation