Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2gqc-6j2q-83qp | RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz` |
Fri, 23 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustcrypto cmov
|
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:rustcrypto:cmov:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Rustcrypto cmov
|
|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustcrypto
Rustcrypto utils |
|
| Vendors & Products |
Rustcrypto
Rustcrypto utils |
Thu, 15 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (portable version). This vulnerability is fixed in 0.4.4. | |
| Title | RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-15T19:57:48.741Z
Reserved: 2026-01-13T18:22:43.980Z
Link: CVE-2026-23519
Updated: 2026-01-15T19:57:33.242Z
Status : Analyzed
Published: 2026-01-15T20:16:05.313
Modified: 2026-01-23T18:59:58.223
Link: CVE-2026-23519
No data.
OpenCVE Enrichment
Updated: 2026-04-18T06:15:15Z
Github GHSA