PT-2025-22646 · Openssl+2 · Openssl+2

Alicja Kario

+1

·

Published

2025-05-14

·

Updated

2025-07-07

·

CVE-2025-27587

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions openssl-3 (affected versions not specified)
Description The issue concerns a timing side channel vulnerability in the P-384 implementation when used with ECDSA in the PPC architecture. Additionally, there is a missing null pointer check before accessing handshake func in ssl lib.c. This could potentially lead to security issues. There is also an issue with Disabling EMS in OpenSSL configuration, which prevents sshd from starting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-27587
ECHO-3213-E8F7-97F9
OPENSUSE-SU-2025:15183-1
OPENSUSE-SU-2025_1550-1
SUSE-SU-2025:02042-1
SUSE-SU-2025:02236-1
SUSE-SU-2025:1550-1
SUSE-SU-2025:20406-1
SUSE-SU-2025:20417-1
SUSE-SU-2025_02042-1
SUSE-SU-2025_02236-1
SUSE-SU-2025_1550-1

Affected Products

Debian
Openssl
Suse