{"id":"CVE-2022-48570","details":"Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.","modified":"2026-08-12T03:51:30.063576646Z","published":"2023-08-22T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48570.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/weidai11/cryptopp/releases/tag/CRYPTOPP_8_4_0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48570.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48570"},{"type":"REPORT","url":"https://github.com/weidai11/cryptopp/issues/992"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/weidai11/cryptopp","events":[{"introduced":"0"},{"fixed":"434e3189db61ff4ced13b47fe450a42b3c8cb676"}],"database_specific":{"cpe":"cpe:2.3:a:cryptopp:crypto\\+\\+:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"8.4.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["CRYPTOPP_5_6_2","CRYPTOPP_8_3_0","CRYPTOPP_8_2_0","CRYPTOPP_8_1_0","CRYPTOPP_8_0_0","CRYPTOPP_7_0_0","CRYPTOPP_6_0_0","CRYPTOPP_5_6_5","CRYPTOPP_5_6_4","CRYPTOPP_5_6_3","CRYPTOPP_5_6_1","CRYPTOPP_5_6_0","CRYPTOPP_5_5_2","CRYPTOPP_5_5_1","CRYPTOPP_5_5","CRYPTOPP_5_4","CRYPTOPP_5_3_0","CRYPTOPP_5_2_3","CRYPTOPP_5_2_1","CRYPTOPP_5_2","CRYPTOPP_5_1","CRYPTOPP_5_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48570.json"}}],"schema_version":"1.9.0"}