{"id":"CVE-2024-9355","aliases":["GO-2024-3167"],"url":"https://o3.security/vulnerability/CVE-2024-9355","summary":"Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability","details":"A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.","published":"2024-10-01T21:31:34Z","modified":"2026-09-21T18:45:04.700597509Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/golang-fips/openssl","fixedVersion":null}],"fix":{"url":"https://github.com/golang-fips/openssl/pull/198","label":"golang-fips/openssl#198"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9355"},{"type":"WEB","url":"https://github.com/golang-fips/openssl/pull/198"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/4950"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-3167"},{"type":"PACKAGE","url":"https://github.com/golang-fips/openssl"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2315719"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-9355"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:69235"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:68504"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:66016"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:59439"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:55525"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:55520"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7624"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7256"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7118"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2416"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:9551"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8847"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8678"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8327"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7550"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7502"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:10133"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-21T18:45:04.700597509Z"}}