CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
- EPSS probability
- 0.30%
- CWE
- CWE-457
- Published
- 2024-10-01
- Last modified
- 2026-09-17
Affected products
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-78935 — Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to p
- CVE-2026-14405 — Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code insi
- CVE-2024-7022 — Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor
- CVE-2026-13825 — Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap
- CVE-2024-10934 — OpenBSD NFS double-free vulnerability
- CVE-2022-40510 — Buffer copy without checking size of input in Audio.
- CVE-2026-14413 — Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the ren
- CVE-2026-10960 — Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the re