Bug 2351813 (CVE-2020-36843) - CVE-2020-36843 d25519-java: Signature Malleability in EdDSA-Java Leading to SUF-CMA Violation
Summary: CVE-2020-36843 d25519-java: Signature Malleability in EdDSA-Java Leading to S...
Keywords:
Status: NEW
Alias: CVE-2020-36843
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2352360 2352361
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-13 08:03 UTC by OSIDB Bzimport
Modified: 2025-03-13 19:03 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-03-13 08:03:26 UTC
The implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA (Strong Existential Unforgeability under Chosen Message Attacks) property. This allows attackers to create new valid signatures different from previous signatures for a known message.


Note You need to log in before you can comment on or make changes to this bug.