PT-2026-26340 · Wolfssl · Wolfssl

Wind Wong

·

Published

2026-01-01

·

Updated

2026-04-30

·

CVE-2026-3580

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL version 5.8.4
Description The software contains a flaw in the constant-time masking logic within the sp 256 get entry 256 9 function. When compiled with GCC targeting RISC-V RV32I using the -O3 optimization flag, the logic is altered into conditional branches. This change compromises the side-channel resistance of Elliptic Curve Cryptography (ECC) scalar multiplication, potentially enabling a local attacker to retrieve secret keys through timing analysis.
Recommendations Avoid compiling wolfSSL version 5.8.4 with GCC targeting RISC-V RV32I using the -O3 optimization flag.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2026-3580

Affected Products

Wolfssl