Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Low severity
GitHub Reviewed
Published
Jul 27, 2025
to the GitHub Advisory Database
•
Updated Jul 28, 2025
Withdrawn
This advisory was withdrawn on Jul 28, 2025
Description
Published by the National Vulnerability Database
Jul 27, 2025
Published to the GitHub Advisory Database
Jul 27, 2025
Reviewed
Jul 28, 2025
Withdrawn
Jul 28, 2025
Last updated
Jul 28, 2025
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-x4gp-pqpj-f43q. This link is maintained to preserve external references.
Original Description
The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.
References