PT-2024-39589 · Openssl+5 · Golang Fips Openssl+5

David Benoit

·

Published

2024-09-30

·

Updated

2025-10-02

·

CVE-2024-9355

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Golang FIPS OpenSSL (affected versions not specified)
Description A flaw in Golang FIPS OpenSSL allows a malicious user to cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. This may also lead to a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker sends a zeroed buffer in place of a pre-computed sum. Additionally, it is possible to force a derived key to be all zeros instead of an unpredictable value, which may have implications for the Go TLS stack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7502
ALSA-2024:7550
ALSA-2024:8327
ALSA-2024:8678
ALSA-2024:8847
ALSA-2025:7118
ALSA-2025:7256
AZL-52774
CESA-2024_7502
CESA-2024_8327
CESA-2024_8847
CVE-2024-9355
GHSA-3H3X-2HWV-HR52
GO-2024-3167
INFSA-2024_7502
INFSA-2024_7550
INFSA-2024_8327
INFSA-2024_8678
INFSA-2024_8847
INFSA-2025_7118
INFSA-2025_7256
OESA-2025-1052
OESA-2025-1053
OESA-2025-1054
OESA-2025-1055
OESA-2025-1056
OESA-2025-1124
OESA-2025-1167
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
RHSA-2024:10133
RHSA-2024:7502
RHSA-2024:7550
RHSA-2024:8327
RHSA-2024:8678
RHSA-2024:8847
RHSA-2024:9551
RHSA-2024_7502
RHSA-2024_7550
RHSA-2024_8327
RHSA-2024_8678
RHSA-2024_8847
RHSA-2025:7118
RHSA-2025:7256
RHSA-2025:7624
RHSA-2025_7118
RHSA-2025_7256
RLSA-2024:7502
RLSA-2024:7550
RLSA-2024:8327
RLSA-2024:8678
RLSA-2024:8847
SUSE-SU-2024:3911-1

Affected Products

Almalinux
Centos
Golang Fips Openssl
Red Hat
Rocky Linux
Suse