Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

build: Update module github.com/cloudflare/circl to v1.6.1 [SECURITY] (releases/v5.x)#1741

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation

@go-git-renovate
Copy link
Contributor

@go-git-renovatego-git-renovatebot commentedNov 23, 2025
edited
Loading

This PR contains the following updates:

PackageChangeAgeConfidence
github.com/cloudflare/circlv1.3.7 ->v1.6.1ageconfidence

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

CVE-2025-8556 /GHSA-2x5j-vhc8-9cwm /GO-2025-3754

More information

Details

Impact

The CIRCL implementation of FourQ fails to validate user-supplied low-order points during Diffie-Hellman key exchange, potentially allowing attackers to force the identity point and compromise session security.

Moreover, there is an incorrect point validation in ScalarMult can lead to incorrect results in the isEqual function and if a point is on the curve.

Patches

Version 1.6.1 (https://github.com/cloudflare/circl/tree/v1.6.1) mitigates the identified issues.

We acknowledge Alon Livne (Botanica Software Labs) for the reported findings.

Severity

  • CVSS Score: 3.7 / 10 (Low)
  • Vector String:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided byOSV and theGitHub Advisory Database (CC-BY 4.0).


CIRCL-Fourq: Missing and wrong validation can lead to incorrect results in github.com/cloudflare/circl

CVE-2025-8556 /GHSA-2x5j-vhc8-9cwm /GO-2025-3754

More information

Details

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results in github.com/cloudflare/circl

Severity

Unknown

References

This data is provided byOSV and theGo Vulnerability Database (CC-BY 4.0).


Release Notes

cloudflare/circl (github.com/cloudflare/circl)

v1.6.1: CIRCL v1.6.1

Compare Source

CIRCL v1.6.1

  • Fixes some point checks on the FourQ curve.
  • Hybrid KEM fails on low-order points.
What's Changed

Full Changelog:cloudflare/circl@v1.6.0...v1.6.1

v1.6.0: CIRCL v1.6.0

Compare Source

CIRCL v1.6.0

New!
What's Changed
New Contributors

Full Changelog:cloudflare/circl@v1.5.0...v1.6.0

v1.5.0: CIRCL v1.5.0

Compare Source

CIRCL v1.5.0

New: ML-DSA, Module-Lattice-based Digital Signature Algorithm.

What's Changed
New Contributors

Full Changelog:cloudflare/circl@v1.4.0...v1.5.0

v1.4.0: CIRCL v1.4.0

Compare Source

CIRCL v1.4.0

Changes

New: ML-KEM compatible with FIPS-203.

Commit History

Full Changelog:cloudflare/circl@v1.3.9...v1.4.0

v1.3.9: CIRCL v1.3.9

Compare Source

CIRCL v1.3.9

Changes:
  • Fix bug on BLS12381 decoding elements.
Commit History

Full Changelog:cloudflare/circl@v1.3.8...v1.3.9

v1.3.8: CIRCL v1.3.8

Compare Source

CIRCL v1.3.8

New

  • BLS Signatures on top of BLS12-381.
  • Adopt faster squaring in pairings.
  • BlindRSA compliant with RFC9474.
  • (Verifiable) Secret Sharing compatible with the Group interface (elliptic curves).

Notice

What's Changed
New Contributors

Full Changelog:cloudflare/circl@v1.3.7...v1.3.8


Configuration

📅Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated byRenovate Bot.

@go-git-renovatego-git-renovatebot added the dependenciesPull requests that update a dependency file labelNov 23, 2025
@go-git-renovatego-git-renovatebot changed the titlechore(deps): update module github.com/cloudflare/circl to v1.6.1 [security] (releases/v5.x)build: Update module github.com/cloudflare/circl to v1.6.1 [SECURITY] (releases/v5.x)Nov 23, 2025
@go-git-renovatego-git-renovatebotforce-pushed therenovate/releases/v5.x-go-github.com-cloudflare-circl-vulnerability branch from564a0a3 to3aa3068CompareNovember 23, 2025 21:22
@go-git-renovatego-git-renovatebotforce-pushed therenovate/releases/v5.x-go-github.com-cloudflare-circl-vulnerability branch from3aa3068 toacc28f1CompareNovember 23, 2025 21:58
@pjbgfpjbgf merged commit3a31754 intoreleases/v5.xNov 23, 2025
24 checks passed
@pjbgfpjbgf deleted the renovate/releases/v5.x-go-github.com-cloudflare-circl-vulnerability branchNovember 23, 2025 22:16
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@pjbgfpjbgfpjbgf approved these changes

Assignees

No one assigned

Labels

dependenciesPull requests that update a dependency file

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@pjbgf

[8]ページ先頭

©2009-2025 Movatter.jp