Description
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.7.4-relnotes.txt
Third Party Advisory x_refsource_misc
https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/
Vendor Advisory x_refsource_misc
https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.6.5-relnotes.txt
Scores
CVSS v3
4.7
EPSS
0.0015
EPSS Percentile
35.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (5)
openbsd/libressl
2.7.0
openbsd/libressl
2.7.1
openbsd/libressl
2.7.2
openbsd/libressl
2.7.3
openbsd/libressl
< 2.6.5
Published
Jun 15, 2018
Tracked Since
Feb 18, 2026