Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast network connection with low latency.
There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This can happen with significant probability only for some of the supported elliptic curves. In particular the NIST P-521 curve is affected. To be able to measure this leak, the attacker process must either be located in the same physical computer or must have a very fast network connection with low latency. For that reason the severity of this vulnerability is Low.
The FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue.
CVSS Details
- CVSS 3.1 Base Score: 4.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mecabUpgrade mecab-develUpgrade mecab-ipadicUpgrade rapidjson-develUpgrade mecab-ipadic-EUCJPUpgrade mysqlUpgrade mysql-develUpgrade mysql-testUpgrade mysql-libsUpgrade rapidjson-docUpgrade mysql-test-dataUpgrade mysql-errmsgUpgrade mysql-serverUpgrade mysql-common | Sep 19, 2025 | Sep 17, 2025 |
| Alpine Linux | — | Upgrade openssl | Aug 8, 2025 | Jan 20, 2025 |
| Amazon Linux Ami 2 | — | Upgrade openssl-snapsafe-staticUpgrade opensslUpgrade edk2-tools-docUpgrade aws-cfn-bootstrapUpgrade openssl11-staticUpgrade openssl-perlUpgrade openssl11-develUpgrade edk2-toolsUpgrade openssl11-libsUpgrade openssl11Upgrade edk2-ovmfUpgrade openssl-snapsafe-develUpgrade openssl-develUpgrade edk2-debuginfoUpgrade openssl11-debuginfoUpgrade openssl-libsUpgrade openssl-staticUpgrade openssl-snapsafeUpgrade openssl-debuginfoUpgrade openssl-snapsafe-perlUpgrade openssl-snapsafe-debuginfoUpgrade openssl-snapsafe-libsUpgrade edk2-aarch64 | Feb 5, 2025 | Jan 20, 2025 |
| Amazon_linux_2023 | — | Upgrade openssl-debugsourceUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-develUpgrade openssl-snapsafe-libs-debuginfoUpgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-snapsafe-libs | Mar 10, 2025 | Jan 20, 2025 |
| Debian | — | Upgrade edk2Upgrade openssl | May 15, 2025 | Jan 20, 2025 |
| Dell Poweredge Dsa2025289 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | Jul 16, 2025 |
| Dell Powerstore Dsa2025223 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 27, 2025 |
| Dell Powerstore Dsa2025342 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Sep 2, 2025 |
| Dell Powerstore Dsa2026039 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Jan 6, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 5, 2026 | Jan 20, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl | May 13, 2025 | Jan 20, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade opensslUpgrade openssl-pkcs11Upgrade openssl-libsUpgrade openssl-perl | Apr 11, 2025 | Jan 20, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-pkcs11 | May 7, 2025 | Jan 20, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libs | Apr 1, 2025 | Jan 20, 2025 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libs | Mar 18, 2025 | Jan 20, 2025 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory44 | Feb 25, 2025 | Jan 20, 2025 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.42Upgrade to MySQL version 9.3.0Upgrade to MySQL version 8.4.5 | Apr 16, 2025 | Jan 20, 2025 |
| Oracle_linux | — | Upgrade mysql-selinuxUpgrade mysql-errmsgUpgrade mysql8.4-errmsgUpgrade mysql-develUpgrade mysql8.4-serverUpgrade mysql8.4-commonUpgrade mysql-libsUpgrade mysql-test-dataUpgrade mecab-develUpgrade mecab-ipadicUpgrade mysql-testUpgrade mysql-commonUpgrade mysql8.4-libsUpgrade rapidjson-docUpgrade mysql8.4-test-dataUpgrade mysqlUpgrade mecab-ipadic-EUCJPUpgrade rapidjson-develUpgrade mysql8.4Upgrade mysql-serverUpgrade mecabUpgrade mysql8.4-develUpgrade mysql8.4-test | Sep 15, 2025 | Jan 20, 2025 |
| Redhat_linux | — | Upgrade mecab-debugsource-0.996Upgrade mysql-common-8.4.6Upgrade mysql-devel-8.4.6Upgrade mysql-8.4.6Upgrade mecab-ipadic-2.7.0.20070801Upgrade mysql-test-debuginfo-8.4.6Upgrade mecab-0.996Upgrade mysql-test-data-8.4.6Upgrade mysql-debuginfo-8.4.6Upgrade rapidjson-devel-1.1.0Upgrade mecab-debuginfo-0.996Upgrade mecab-devel-0.996Upgrade mysql-server-debuginfo-8.4.6Upgrade mysql-test-8.4.6Upgrade mysql-debugsource-8.4.6Upgrade rapidjson-doc-1.1.0Upgrade mecab-ipadic-EUCJP-2.7.0.20070801Upgrade mysql-devel-debuginfo-8.4.6Upgrade mysql-libs-8.4.6Upgrade mysql-errmsg-8.4.6Upgrade mysql-server-8.4.6Upgrade mysql-libs-debuginfo-8.4.6No solution exists | Jul 9, 2025 | Jan 20, 2025 |
| Rocky_linux | — | Upgrade mysql8.4-devel-debuginfoUpgrade mysql8.4-server-debuginfoUpgrade mysql8.4-libs-debuginfoUpgrade mysql8.4-libsUpgrade mysql8.4-test-debuginfoUpgrade mysql8.4-serverUpgrade mysql8.4-develUpgrade mysql8.4Upgrade mysql8.4-debugsourceUpgrade mysql8.4-debuginfoUpgrade mysql8.4-test | Feb 5, 2026 | Oct 3, 2025 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.4.3Upgrade Splunk Universal Forwarder to version 9.2.7Upgrade Splunk Universal Forwarder to version 9.4.3Upgrade Splunk Enterprise to version 9.3.5Upgrade Splunk Enterprise to version 9.2.7Upgrade Splunk Universal Forwarder to version 9.1.10Upgrade Splunk Universal Forwarder to version 9.3.5Upgrade Splunk Enterprise to version 9.1.10 | Sep 30, 2025 | Jan 20, 2025 |
| Suse | — | Upgrade libopenssl-1_1-develUpgrade libopenssl-3-fips-provider-32bitUpgrade libopenssl1_1-32bitUpgrade openssl-1_1Upgrade libopenssl-3-devel-32bitUpgrade libopenssl3Upgrade libopenssl-3-fips-provider-x86-64-v3Upgrade libopenssl-3-develUpgrade openssl-3Upgrade openssl-3-docUpgrade libopenssl3-32bitUpgrade libopenssl1_1Upgrade libopenssl1_1-hmacUpgrade libopenssl-3-fips-providerUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl3-x86-64-v3Upgrade openssl-1_1-docUpgrade libopenssl1_1-hmac-32bit | Dec 5, 2025 | Sep 20, 2025 |
| Ubuntu | — | Upgrade qemu-efiUpgrade ovmfUpgrade qemu-efi-armUpgrade libssl3t64Upgrade libssl1.1Upgrade qemu-efi-aarch64Upgrade qemu-efi-riscv64Upgrade libssl3Upgrade qemu-efi-loongarch64Upgrade opensslUpgrade ovmf-ia32 | Feb 12, 2025 | Jan 20, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 22, 2026 | Jan 20, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub