An issue was discovered in wolfSSL before 5.7.0. A safe...
Moderate severity
Unreviewed
Published
Aug 27, 2024
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 27, 2024
Published to the GitHub Advisory Database
Aug 27, 2024
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys,
such as in server-side TLS connections, the connection is halted if any fault occurs. The success rate in a certain amount of connection requests can be processed via an advanced technique for ECDSA key recovery.
References