{"id":"UBUNTU-CVE-2024-50382","details":"Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.","modified":"2026-05-20T16:19:24.409342774Z","published":"2024-10-23T17:15:00Z","related":["USN-7586-1"],"upstream":["CVE-2024-50382"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-50382"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-50382"},{"type":"REPORT","url":"https://github.com/randombit/botan/compare/3.5.0...3.6.0"},{"type":"REPORT","url":"https://arxiv.org/pdf/2410.13489"},{"type":"REPORT","url":"https://news.ycombinator.com/item?id=41887153"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7586-1"}],"affected":[{"package":{"name":"botan","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/botan?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.0-3","2.4.0-4","2.4.0-5ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.4.0-5ubuntu1"},{"binary_name":"libbotan-2-4","binary_version":"2.4.0-5ubuntu1"},{"binary_name":"python3-botan","binary_version":"2.4.0-5ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"botan","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/botan?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.9.0-2","2.9.0-2build1","2.12.1-2","2.12.1-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.12.1-2build1"},{"binary_name":"libbotan-2-12","binary_version":"2.12.1-2build1"},{"binary_name":"python3-botan","binary_version":"2.12.1-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"oscar","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/oscar?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.0-testing-3-1","1.1.0-testing-3-2","1.1.0-testing-3-3","1.1.0-testing-3-3build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.0-testing-3-3build1","binary_name":"oscar"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"oscar","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/oscar?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.0-1","1.3.0-1","1.3.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"oscar","binary_version":"1.3.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"botan","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/botan?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.19.1+dfsg-2ubuntu1+esm1"}]}],"versions":["2.17.3+dfsg-3","2.19.1+dfsg-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"},{"binary_name":"libbotan-2-19","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"},{"binary_name":"python3-botan","binary_version":"2.19.1+dfsg-2ubuntu1+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"oscar","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/oscar?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.0-1","1.5.1-1","1.5.1-1build1","1.5.1-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"oscar","binary_version":"1.5.1-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"botan","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/botan?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.19.3+dfsg-1ubuntu2+esm1"}]}],"versions":["2.19.3+dfsg-1ubuntu1","2.19.3+dfsg-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"botan","binary_version":"2.19.3+dfsg-1ubuntu2+esm1"},{"binary_name":"libbotan-2-19","binary_version":"2.19.3+dfsg-1ubuntu2+esm1"},{"binary_name":"python3-botan","binary_version":"2.19.3+dfsg-1ubuntu2+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"oscar","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/oscar?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.3-2"],"ecosystem_specific":{"binaries":[{"binary_name":"oscar","binary_version":"1.5.3-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}},{"package":{"name":"oscar","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/oscar?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.3-2","1.5.3-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"oscar","binary_version":"1.5.3-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-50382.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}