Back

LOW

Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V

Published Mar 19, 2026

Description

In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-channel resistance of ECC scalar multiplication, potentially allowing a local attacker to recover secret keys via timing analysis.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Mar 19, 2026
Updated Mar 19, 2026
Reserved Mar 5, 2026
CISA Vulnrichment
Updated Mar 19, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner wolfSSL
Published Mar 19, 2026
Updated Mar 19, 2026
Exploited since n/a
EUVD-2026-13172