{"schema_version":"1.7.3","id":"GHSA-78hx-gp6g-7mj6","published":"2024-03-20T18:10:36Z","modified":"2026-07-08T06:29:41.110680680Z","aliases":["CVE-2024-1394","GO-2024-2660"],"summary":"Memory leaks in code encrypting and verifying RSA payloads","details":"Using crafted public RSA keys which are not compliant with SP 800-56B can cause a small memory leak when encrypting and verifying payloads.\n\nAn attacker can leverage this flaw to gradually erode available memory to the point where the host crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.","affected":[{"package":{"name":"github.com/golang-fips/go","ecosystem":"Go","purl":"pkg:golang/github.com/golang-fips/go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.22.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json"}},{"package":{"name":"github.com/golang-fips/openssl/v2","ecosystem":"Go","purl":"pkg:golang/github.com/golang-fips/openssl/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 2.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json"}},{"package":{"name":"github.com/microsoft/go-crypto-openssl","ecosystem":"Go","purl":"pkg:golang/github.com/microsoft/go-crypto-openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.2.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json"}},{"package":{"name":"github.com/microsoft/go-crypto-openssl/openssl","ecosystem":"Go","purl":"pkg:golang/github.com/microsoft/go-crypto-openssl/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.9"}]}],"database_specific":{"last_known_affected_version_range":"<= 0.2.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-78hx-gp6g-7mj6/GHSA-78hx-gp6g-7mj6.json"}}],"references":[{"type":"WEB","url":"https://github.com/golang-fips/openssl/security/advisories/GHSA-78hx-gp6g-7mj6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1394"},{"type":"WEB","url":"https://github.com/microsoft/go-crypto-openssl/commit/104fe7f6912788d2ad44602f77a0a0a62f1f259f"},{"type":"WEB","url":"https://github.com/golang-fips/openssl/commit/85d31d0d257ce842c8a1e63c4d230ae850348136"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1462"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4378"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4379"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4502"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4581"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4591"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4672"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4699"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4761"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4762"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4960"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:5258"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:5634"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7262"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-1394"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2262921"},{"type":"PACKAGE","url":"https://github.com/golang-fips/openssl"},{"type":"WEB","url":"https://github.com/golang-fips/openssl/releases/tag/v2.0.1"},{"type":"WEB","url":"https://github.com/microsoft/go-crypto-openssl/releases/tag/v0.2.9"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2660"},{"type":"WEB","url":"https://vuln.go.dev/ID/GO-2024-2660.json"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1468"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1472"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1501"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1502"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1561"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1563"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1566"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1567"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1574"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1640"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1644"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1646"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1763"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:1897"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2562"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2568"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2569"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2729"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2730"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:2767"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:3265"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:3352"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4146"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4371"}],"database_specific":{"cwe_ids":["CWE-400","CWE-401"],"github_reviewed":true,"github_reviewed_at":"2024-03-20T18:10:36Z","nvd_published_at":"2024-03-21T13:00:08Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}