PT-2026-26340 · Wolfssl · Wolfssl

·

CVE-2026-3580

·

Published

2026-01-01

·

Updated

2026-04-30

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wolfSSL version 5.8.4
Description The software contains a flaw in the constant-time masking logic within the sp 256 get entry 256 9 function. When compiled with GCC targeting RISC-V RV32I using the -O3 optimization flag, the logic is altered into conditional branches. This change compromises the side-channel resistance of Elliptic Curve Cryptography (ECC) scalar multiplication, potentially enabling a local attacker to retrieve secret keys through timing analysis.
Recommendations Avoid compiling wolfSSL version 5.8.4 with GCC targeting RISC-V RV32I using the -O3 optimization flag.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3580

Affected Products

Wolfssl