← Back to CVE List

CVE-2023-26557

Published: 2023-04-21T18:15Z
Last Modified: 2025-02-05T15:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, modular exponentiation, or modular inverse. An example leak is in crypto/paillier/paillier.go. (bnb-chain/tss-lib and thorchain/tss are also affected.) > MITRE Terms of Use apply – see LICENSE‑MITRE.txt