PT-2026-26340 · Wolfssl · Wolfssl

Wind Wong

·

Publicado

2026-01-01

·

Atualizado

2026-04-30

·

CVE-2026-3580

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL version 5.8.4
Description The software contains a flaw in the constant-time masking logic within the sp 256 get entry 256 9 function. When compiled with GCC targeting RISC-V RV32I using the -O3 optimization flag, the logic is altered into conditional branches. This change compromises the side-channel resistance of Elliptic Curve Cryptography (ECC) scalar multiplication, potentially enabling a local attacker to retrieve secret keys through timing analysis.
Recommendations Avoid compiling wolfSSL version 5.8.4 with GCC targeting RISC-V RV32I using the -O3 optimization flag.

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3580

Produtos afetados

Wolfssl