CVE-2024-56430

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Dec 25, 2024
Updated: Dec 26, 2024
CWE ID 476

Summary

CVE-2024-56430 is a newly disclosed vulnerability affecting OpenFHE versions up to 1.2.3. This issue involves a NULL pointer dereference in the BinFHEContext::EvalFloor function within the lib/binfhe-base-scheme.cpp file. If exploited, an attacker could cause the software to crash or potentially execute arbitrary code with the privileges of the affected system. This vulnerability poses a significant risk to users running OpenFHE and is advised to be patched as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share