Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
updated 3 weeks, 3 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • pscircle
    • libcircle
    • circle-flags
    • circleci-cli
    • pkgsRocm.libcircle
    • tela-circle-icon-theme
    • numix-icon-theme-circle
    • typstPackages.cross-circle
    • haskellPackages.circle-packing
    • typstPackages.cross-circle_1_0_0
  • @LeSuisse dismissed
Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 .

Affected products

CIRCL
  • <1.6.3
Ignored packages (10)

pkgs.libcircle

API for distributing embarrassingly parallel workloads using self-stabilization

Not directly present in nixpkgs