PT-2026-23915 · Dropbear · Dropbear
Pythok
·
Published
2026-03-08
·
Updated
2026-03-08
·
CVE-2026-3706
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dropbear versions up to 2025.89
Description
A flaw exists in mkj Dropbear that relates to improper verification of cryptographic signatures. This issue stems from a manipulation within the
unpackneg function located in the src/curve25519.c file, specifically within the S Range Check component. The attack can be initiated remotely and is considered to have high complexity, with difficult exploitability. The exploit has been publicly disclosed. The issue undermines integrity and auditing of Ed25519 signatures, allowing crafted signatures to be accepted.Recommendations
Deploy the patch fdec3c90a15447bd538641d85e5a3e3ac981011d.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dropbear