CVE-2025-22866
Estado: AplazadaMedia (4)—
Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-22866",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-22866",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-10T20:40:17.232803Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "security@golang.org",
"affectedData": [
{
"vendor": "Go standard library",
"product": "crypto/internal/nistec",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.22.12",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.23.0-0",
"lessThan": "1.23.6",
"versionType": "semver"
},
{
"status": "affected",
"version": "1.24.0-0",
"lessThan": "1.24.0-rc.3",
"versionType": "semver"
}
],
"packageName": "crypto/internal/nistec",
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "p256NegCond"
},
{
"name": "P256Point.ScalarBaseMult"
},
{
"name": "P256Point.ScalarMult"
},
{
"name": "P256Point.SetBytes"
}
]
}
]
}
],
"published": "2025-02-06T17:15:21.410",
"references": [
{
"url": "https://go.dev/cl/643735",
"source": "security@golang.org"
},
{
"url": "https://go.dev/issue/71383",
"source": "security@golang.org"
},
{
"url": "https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k",
"source": "security@golang.org"
},
{
"url": "https://pkg.go.dev/vuln/GO-2025-3447",
"source": "security@golang.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20250221-0002/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols."
},
{
"lang": "es",
"value": "Debido al uso de una instrucción de tiempo variable en la implementación de ensamblaje de una función interna, se filtra una pequeña cantidad de bits de escalares secretos en la arquitectura ppc64le. Debido a la forma en que se utiliza esta función, no creemos que esta filtración sea suficiente para permitir la recuperación de la clave privada cuando se utiliza P-256 en cualquier protocolo conocido."
}
],
"lastModified": "2026-06-17T08:50:38.563",
"sourceIdentifier": "security@golang.org"
}