{"id":"CVE-2024-9355","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-9355","summary":"A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in…","details":"A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.","published":"2024-10-01T19:15:09.793","modified":"2026-08-08T02:17:15.940","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/golang-fips/openssl/pull/198","label":"golang-fips/openssl#198"},"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:10133"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7502"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7550"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8327"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8678"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8847"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:9551"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2416"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7118"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7256"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7624"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-9355"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2315719"},{"type":"WEB","url":"https://github.com/golang-fips/openssl/pull/198"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T02:17:15.940"}}