PT-2021-6992 · Openssl+1 · Openssl+1

Bernd Edlinger

·

Published

2021-12-10

·

Updated

2026-04-27

·

CVE-2021-4160

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2zb OpenSSL versions 1.1.1 through 1.1.1l OpenSSL version 3.0.0
Description The issue is related to a carry propagation bug in the MIPS32 and MIPS64 squaring procedure of the OpenSSL library, which can lead to the compromise of elliptic curve algorithms, including some of the TLS 1.3 default curves. This bug may allow a remote attacker to disclose protected information, particularly if private keys are reused. However, the prerequisites for an attack are considered unlikely, and the impact was not analyzed in detail. The amount of resources required for such an attack would be significant.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2zb, update to version 1.0.2zc or apply the fix from git commit 6fc1aaaf3. For OpenSSL versions 1.1.1 through 1.1.1l, update to version 1.1.1m. For OpenSSL version 3.0.0, update to version 3.0.1.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1227
ALT-PU-2022-1515
ALT-PU-2022-1543
ALT-PU-2022-1562
AZL-8472
BDU:2022-02820
CVE-2021-4160
DSA-5103-1
JLSEC-2026-226

Affected Products

Alt Linux
Openssl