Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
GHSA-3h3x-2hwv-hr52 · CVE-2024-9355 · GO-2024-3167
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-9355
- WEB https://github.com/golang-fips/openssl/pull/198
- WEB https://github.com/github/advisory-database/pull/4950
- WEB https://pkg.go.dev/vuln/GO-2024-3167
- PACKAGE https://github.com/golang-fips/openssl
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2315719
- WEB https://access.redhat.com/security/cve/CVE-2024-9355
- WEB https://access.redhat.com/errata/RHSA-2026:69235
- WEB https://access.redhat.com/errata/RHSA-2026:68504
- WEB https://access.redhat.com/errata/RHSA-2026:66016
- WEB https://access.redhat.com/errata/RHSA-2026:59439
- WEB https://access.redhat.com/errata/RHSA-2026:55525
- WEB https://access.redhat.com/errata/RHSA-2026:55520
- WEB https://access.redhat.com/errata/RHSA-2025:7624
- WEB https://access.redhat.com/errata/RHSA-2025:7256
- WEB https://access.redhat.com/errata/RHSA-2025:7118
- WEB https://access.redhat.com/errata/RHSA-2025:2416
- WEB https://access.redhat.com/errata/RHSA-2024:9551
- WEB https://access.redhat.com/errata/RHSA-2024:8847
- WEB https://access.redhat.com/errata/RHSA-2024:8678
- WEB https://access.redhat.com/errata/RHSA-2024:8327
- WEB https://access.redhat.com/errata/RHSA-2024:7550
- WEB https://access.redhat.com/errata/RHSA-2024:7502
- WEB https://access.redhat.com/errata/RHSA-2024:10133
Ready to move
Start Securing
Free, no credit card | First findings in minutes