PT-2026-26340 · Wolfssl · Wolfssl
Wind Wong
·
Publicado
2026-01-01
·
Atualizado
2026-04-30
·
CVE-2026-3580
CVSS v3.1
4.7
Média
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL version 5.8.4
Description
The software contains a flaw in the constant-time masking logic within the
sp 256 get entry 256 9 function. When compiled with GCC targeting RISC-V RV32I using the -O3 optimization flag, the logic is altered into conditional branches. This change compromises the side-channel resistance of Elliptic Curve Cryptography (ECC) scalar multiplication, potentially enabling a local attacker to retrieve secret keys through timing analysis.Recommendations
Avoid compiling wolfSSL version 5.8.4 with GCC targeting RISC-V RV32I using the -O3 optimization flag.
Correção
Side Channel Attack
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wolfssl