CVE-2026-3579
EUVD-2026-1317019.03.2026, 20:16
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This affects multiple SP math functions (sp_256_mul_9, sp_256_sqr_9, etc.), leading to a timing side-channel that may expose sensitive cryptographic data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wolfssl | wolfssl | 5.8.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases