Tools AI-Found Vulnerability Register aifv-0045
Register entry
OpenSSL out-of-bounds memory access from invalid GF(2^m) parameters, found by a Google OSS-Fuzz-Gen harness
- CVE
- CVE-2024-9143
- Project
- OpenSSL
- Component
- low-level GF(2^m) elliptic curve parameters
- Finder
- Google OSS-Fuzz-Gen
- Autonomy
- LLM-generated fuzz target run on OSS-Fuzz
- Evidence tier
- Credits array names the finder
- Assigner
- openssl
- Severity
- Low (OpenSSL severity policy)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
The cleanest attribution in the register: a CVE record naming an AI-generated fuzz harness as finder. It is the one entry with a CVE in the oss-fuzz-gen README's table of 30 bugs found by generated targets.
Credit as recorded: finder: "Google OSS-Fuzz-Gen"; remediation developer: Viktor Dukhovni. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- google/oss-fuzz-gen READMEraw.githubusercontent.com/google/oss-fuzz-gen/main/README.md
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026