Database/Kernel, userspace & hypervisor
Go FIPS OpenSSL: FIPS-mode zeroed buffers can force HMAC false matches and all-zero derived keys
Impact
In Red Hat's FIPS-enabled Go crypto backend, an uninitialised buffer length with a zeroed buffer can be returned in FIPS mode. The consequences the advisory names are the serious ones: a trusted computed HMAC can falsely match an attacker-supplied all-zero sum, and a derived key can come out all zeros instead of unpredictable - with knock-on effects for the Go TLS stack. Nearly every control-plane component a GPU fleet runs is Go built against this backend on RHEL - kubelet, container runtimes, registries, operators, monitoring agents - so on FIPS-mode clusters this weakens authentication-tag checks and key derivation across the management path rather than in one product. Exploitation is conditioned on the attacker being able to steer a zeroed buffer into the comparison, which is why Red Hat rates it moderate rather than critical. It only applies to FIPS mode with the Red Hat Go toolchain; upstream non-FIPS Go builds are unaffected.
Who can reach it
Local per the CVSS vector, requiring low privileges and no user interaction; the practical precondition is a FIPS-mode host running Go binaries built against the golang-fips OpenSSL backend, where an attacker can supply the untrusted sum or influence key derivation input.
What to do
Rebuild or update affected Go components against the fixed golang toolchain - Red Hat has shipped errata RHSA-2024:7502, 7550, 8327, 8678 and 10133 across RHEL 7 ELS, 8 and 9 streams. Because the flaw is compiled into each Go binary, updating the toolchain package is not enough on its own: vendored and container-shipped Go binaries need their own rebuilt versions, and each affected daemon must be restarted after replacement.
References
Related entries
- Linux kernel (drivers/gpu/drm/radeon): The radeon video-encode command-stream parser used an uninitialised stack valueCVE-2025-21996 · Linux kernel (drivers/gpu/drm/radeon)Medium
- Linux kernel (drivers/gpu/drm/xe): The Xe userptr path takes folio locks while holding the MMU notifier lock, whichCVE-2025-37868 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (drivers/vfio/pci/xe): Resetting a passed-through Intel GPU virtual function that does not supportCVE-2026-31601 · Linux kernel (drivers/vfio/pci/xe)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.