CVE Vulnerabilities

CVE-2024-58262

Compiler Optimization Removal or Modification of Security-critical Code

Published: Jul 27, 2025 | Modified: Jul 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

Weakness

The developer builds a security-critical protection mechanism into the software, but the compiler optimizes the program such that the mechanism is removed or modified.

References