golang: crypto/elliptic implementations of P-521 and P-384 elliptic curves allow for denial of service
Published Jan 24, 2019
8.2
HIGHCVSS 3.0
EPSS 4.33%
Description
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
Affected products
No data.
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Ceph Storage 2
golang
Will not fix
Red Hat Ceph Storage 3
golang
Will not fix
Red Hat Enterprise Linux 7
golang
Not affected
Red Hat Enterprise Linux 8
go-toolset:rhel8/golang
Will not fix
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.2
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.3
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.4
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.5
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.6
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
golang
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
golang
Will not fix
Red Hat Storage 3
golang
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | golang | Will not fix | n/a |
| Red Hat Ceph Storage 3 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | golang | Not affected | n/a |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.3 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | golang | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | golang | Will not fix | n/a |
| Red Hat Storage 3 | golang | Will not fix | n/a |
stdlib
Go
Introduced 0 Fixed 1.10.8stdlib
Go
Introduced 1.11.0-0 Fixed 1.11.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | stdlib | 0 | 1.10.8 |
| Go | stdlib | 1.11.0-0 | 1.11.5 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:P/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.33% (0.04326) | 90.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.29% (0.04290) | 89.81th | v5 (v2026.06.15) |
| Apr 26, 2026 | 0.98% (0.00981) | 76.85th | v4 (v2025.03.14) |
| Aug 20, 2025 | 2.40% (0.02397) | 84.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.08% (0.01080) | 76.31th | v4 (v2025.03.14) |
| Dec 17, 2024 | 3.52% (0.03517) | 91.42th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.71% (0.01709) | 88.29th | v3 (v2023.03.01) |
| Jul 26, 2024 | 2.31% (0.02309) | 89.84th | v3 (v2023.03.01) |
| Jun 16, 2024 | 3.78% (0.03776) | 91.89th | v3 (v2023.03.01) |
| Jan 18, 2024 | 6.09% (0.06089) | 92.80th | v3 (v2023.03.01) |
| Nov 8, 2023 | 4.65% (0.04649) | 91.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.95% (0.02950) | 89.28th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.31% (0.16306) | 92.84th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.34% (0.13340) | 89.09th | v1 |
| Jan 6, 2022 | 13.34% (0.13340) | 88.96th | v1 |
| Jan 5, 2022 | 3.32% (0.03317) | 82.13th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.32% (0.03317) | 0.00th | v1 |
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00042.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/106740 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-6486 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1668972 Issue Tracking
- https://github.com/golang/go/commit/42b42f71cf8f5956c09e66230293dfb5db652360 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/golang/go/issues/29903 x_refsource_CONFIRMThird Party Advisory
- https://github.com/google/wycheproof x_refsource_MISCThird Party Advisory
- https://groups.google.com/forum/#%21topic/golang-announce/mVeX35iXuSw x_refsource_CONFIRM
- https://groups.google.com/forum/m/#!topic/golang-announce/mVeX35iXuSw
- https://lists.debian.org/debian-lts-announce/2019/02/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-6486
- https://www.cve.org/CVERecord?id=CVE-2019-6486
- https://www.debian.org/security/2019/dsa-4379 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2019/dsa-4380 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.