Disclosure summary
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
Source-reported weakness categories
CWE-457
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2024-9355
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
CVEProject/cvelistV5 releases · RSS-b194258a94bc9dc7e359d58b36faeef0c05
Open original source · Updated Oct 08, 2026
CVE 2026-10-08_0800Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-c24f0582ffac691d6a3fcc4e42944076aa0
Open original source · Updated Oct 08, 2026
CVE 2026-10-08_0700Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-76b4ee9d8cd1b01a19afcfffa8d594f8863
Open original source · Updated Oct 08, 2026
CVE 2026-10-08_0600Z
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- access.redhat.com
- bugzilla.redhat.com
- github.com
PUBLISHED 2024-10-01T15:15:09-04:00
MODIFIED 2026-10-08T11:17:29-04:00
INGESTED 2026-10-08T12:30:36-04:00