QID 995500
Date Published: 2023-10-05
QID 995500: GO (Go) Security Update for github.com/consensys/gnark (GHSA-498w-5j49-vqjg)
For some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of a, for small values there exists a second decomposition for a+r (where r is the modulus the values are being reduced by). The second decomposition was possible due to overflowing the field where the values are defined.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-498w-5j49-vqjg for updates and patch information.
Vendor References
- GHSA-498w-5j49-vqjg -
github.com/advisories/GHSA-498w-5j49-vqjg
CVEs related to QID 995500
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-498w-5j49-vqjg | github.com/consensys/gnark |
|