BCryptGenerateSymmetricKey memory leak
Published Feb 12, 2025
7.5
HIGHCVSS 3.1
EPSS 1.44%
Description
go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak every time. Commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 contains a fix for the issue. The fix is included in versions 1.23.6-2 and 1.22.12-2 of the Microsoft build of go, as well as in the pseudoversion 0.0.0-20250211154640-f49c8e1379ea of the `github.com/microsoft/go-crypto-winnative` Go package.
Affected products
-
- Version < 0.0.0-20250211154640-f49c8e1379eaStatusaffectedConstraints-
- Version < 1.22.12-2StatusaffectedConstraints-
- Version < 1.23.6-2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | GO-Crypto-Winnative | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
github.com/microsoft/go-crypto-winnative
Go
Introduced 0 Fixed 0.0.0-20250211154640-f49c8e1379ea
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/microsoft/go-crypto-winnative | 0 | 0.0.0-20250211154640-f49c8e1379ea |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-4085 Advisory
- https://github.com/advisories/GHSA-29c6-3hcj-89cf Advisory
- https://github.com/microsoft/go-crypto-winnative/commit/f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 x_refsource_MISC
- https://github.com/microsoft/go-crypto-winnative/security/advisories/GHSA-29c6-3hcj-89cf x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2025-25199
Change history (0)
No recorded changes yet.