{"id":"GHSA-pffg-92cg-xf5c","summary":"gnark-crypto's exponentiation in the pairing target group GT using GLV can give incorrect results","details":"### Impact\nWhen the exponent is bigger than `r`, the group order of the pairing target group `GT`, the exponentiation à la GLV (`ExpGLV`) can *sometimes* give incorrect results compared to normal exponentiation (`Exp`). \n\nThe issue impacts all users using `ExpGLV` for exponentiations in `GT`. This does not impact `Exp` and `ExpCyclotomic` which are sound. Also note that GLV methods in G1 and G2 are sound and _not_ impacted.\n\n### Patches\nFix has been implemented in pull request https://github.com/Consensys/gnark-crypto/pull/451 and merged in commit https://github.com/Consensys/gnark-crypto/commit/ec6be1a037f7c496d595c541a8a8d31c47bcfa3d to master branch.\n\nThe fix increased the bounds of the sub-scalars by 1. In fact, since https://github.com/Consensys/gnark-crypto/pull/213, we use a fast scalar decomposition that tradeoffs divisions (needed in the Babai rounding) by right-shifts. We precompute `b=2^m*v/d (m \u003e log2(d))` and then at runtime compute `scalar*b/2^m` (`v` is a lattice vector and `d` the lattice determinant). This increases the bounds on sub-scalars by 1 which we check at runtime before increasing the loop size (we don't target constant-timeness). `m` is chosen to be a machine word twice big than `log2(d)` so that we rarely need to increase the loop size. Hence why the issue happens only *sometimes* if we omit to increase the bounds. This bounds increase was implemented in G1 and G2 but forgot in GT.\n\n### Workarounds\nUpdating to `v0.12.1+`. Alternatively, use `Exp` or `ExpCyclotomic` instead. We are not aware of any users using `ExpGLV` anyway.\n\n### References\n- Fix PR: https://github.com/Consensys/gnark-crypto/pull/451 \n- Fast scalar decomposition PR: https://github.com/Consensys/gnark-crypto/pull/213\n- https://eprint.iacr.org/2015/565 Sec.4.2\n\n### Acknowledgement\nThe vulnerability was reported by [Antonio Sanso](https://github.com/asanso) @ [EF](https://crypto.ethereum.org/).\n","aliases":["GO-2023-2101"],"modified":"2024-05-20T21:55:42Z","published":"2023-10-05T20:57:20Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-10-05T20:57:20Z"},"references":[{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/security/advisories/GHSA-pffg-92cg-xf5c"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/pull/213"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/pull/451"},{"type":"WEB","url":"https://github.com/Consensys/gnark-crypto/commit/ec6be1a037f7c496d595c541a8a8d31c47bcfa3d"},{"type":"WEB","url":"https://eprint.iacr.org/2015/565"},{"type":"PACKAGE","url":"https://github.com/Consensys/gnark-crypto"}],"affected":[{"package":{"name":"github.com/consensys/gnark-crypto","ecosystem":"Go","purl":"pkg:golang/github.com/consensys/gnark-crypto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.12.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-pffg-92cg-xf5c/GHSA-pffg-92cg-xf5c.json"}}],"schema_version":"1.9.0"}