openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack
Published Mar 25, 2014
1.9
LOWCVSS 2.0
EPSS 0.84%
Description
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.
Affected products
No data.
- ≤ 1.0.0l
- 0.9.1c
- 0.9.2b
- 0.9.3
- 0.9.3a
- 0.9.4
- 0.9.5
- 0.9.5
- 0.9.5
- 0.9.5a
- 0.9.5a
- 0.9.5a
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6b
- 0.9.6c
- 0.9.6d
- 0.9.6e
- 0.9.6f
- 0.9.6g
- 0.9.6h
- 0.9.6i
- 0.9.6j
- 0.9.6k
- 0.9.6l
- 0.9.6m
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7a
- 0.9.7b
- 0.9.7c
- 0.9.7d
- 0.9.7e
- 0.9.7f
- 0.9.7g
- 0.9.7h
- 0.9.7i
- 0.9.7j
- 0.9.7k
- 0.9.7l
- 0.9.7m
- 0.9.8
- 0.9.8a
- 0.9.8b
- 0.9.8c
- 0.9.8d
- 0.9.8e
- 0.9.8f
- 0.9.8g
- 0.9.8h
- 0.9.8i
- 0.9.8j
- 0.9.8k
- 0.9.8l
- 0.9.8m
- 0.9.8m
- 0.9.8n
- 0.9.8o
- 0.9.8p
- 0.9.8q
- 0.9.8r
- 0.9.8s
- 0.9.8t
- 0.9.8u
- 0.9.8v
- 0.9.8w
- 0.9.8x
- 0.9.8y
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0a
- 1.0.0b
- 1.0.0c
- 1.0.0d
- 1.0.0e
- 1.0.0f
- 1.0.0g
- 1.0.0h
- 1.0.0i
- 1.0.0j
- 1.0.0k
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue does not affect the version of openssl and openssl097a as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of openssl and openssl098e as shipped with Red Hat Enterprise Linux 6 or 7.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.84% (0.00845) | 56.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.94% (0.00942) | 56.19th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.30% (0.00301) | 51.25th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 19.07th | v3 (v2023.03.01) |
| May 8, 2024 | 0.05% (0.00046) | 16.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (68)
- http://advisories.mageia.org/MGASA-2014-0165.html x_refsource_CONFIRM
- http://eprint.iacr.org/2014/140 x_refsource_MISC
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=2198be3483259de374f91e57d247d0fc667aef29 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00007.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=140266410314613&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140317760000786&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140389274407904&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140389355508263&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140448122410568&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140482916501310&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140621259019789&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140752315422991&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=140904544427729&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/58492 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/58727 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/58939 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59040 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59162 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59175 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59264 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59300 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59364 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59374 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59413 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59438 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59445 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59450 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59454 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59490 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59495 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59514 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59655 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59721 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60571 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT6443 x_refsource_CONFIRM
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl vendor-advisoryx_refsource_CISCO
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21673137 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676035 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676062 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676419 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676424 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676501 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676655 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21677695 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21677828 x_refsource_CONFIRM
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:067 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/support/kb/doc.php?id=7015264 x_refsource_CONFIRM
- http://www.novell.com/support/kb/doc.php?id=7015300 x_refsource_CONFIRM
- http://www.openssl.org/news/secadv_20140605.txt x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/66363 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2165-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-0076 Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=505278 x_refsource_CONFIRM
- https://bugzilla.novell.com/show_bug.cgi?id=869945 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1080276 Issue Tracking
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10075 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-0076
- https://www.cve.org/CVERecord?id=CVE-2014-0076
Change history (0)
No recorded changes yet.