RUSTSEC-2024-0344

    Dashboard / Vulnerabilities / RUSTSEC-2024-0344

    RUSTSEC-2024-0344

    Published: 18 Jun 2024Last Modified: 28 Oct 2025

    Summary: Timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`

    Details: Timing variability of any kind is problematic when working with potentially secret values such as elliptic curve scalars, and such issues can potentially leak private keys and other secrets. Such a problem was recently discovered in `curve25519-dalek`. The `Scalar29::sub` (32-bit) and `Scalar52::sub` (64-bit) functions contained usage of a mask value inside a loop where LLVM saw an opportunity to insert a branch instruction (`jns` on x86) to conditionally bypass this code section when the mask value is set to zero as can be seen in godbolt: - 32-bit (see L106): <https://godbolt.org/z/zvaWxzvqv> - 64-bit (see L48): <https://godbolt.org/z/PczYj7Pda> A similar problem was recently discovered in the Kyber reference implementation: <https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/hqbtIGFKIpU/m/cnE3pbueBgAJ> As discussed on that thread, one portable solution, which is also used in this PR, is to introduce a volatile read as an optimization barrier, which prevents the compiler from optimizing it away. The fix can be validated in godbolt here: - 32-bit: <https://godbolt.org/z/jc9j7eb8E> - 64-bit: <https://godbolt.org/z/x8d46Yfah> The problem was discovered and the solution independently verified by Alexander Wagner <[email protected]> and Lea Themint <[email protected]> using their DATA tool: <https://github.com/Fraunhofer-AISEC/DATA>

    Affected packages

    Package

    Name: curve25519-dalek

    Purl: pkg:cargo/curve25519-dalek

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -4.1.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2024-0344 | CVE-DB