关键漏洞信息 漏洞详情 CVE编号: CVE-2025-8556, GHSA-2x5j-vhc8-9cwm 漏洞ID: Bug 2371624 产品: Security Response 组件: vulnerability 优先级: Low 严重性: Low 操作系统: Linux 影响描述 The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security. Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve. 修复措施 Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues. 报告者与时间 报告人: OSIDB Bzimport 报告时间: 2025-06-11 00:01 UTC 修改时间: 2025-08-04 19:11 UTC