CVE-2026-3503: Fault injection attack with ML-DSA and ML-KEM on ARM

Published Mar 19, 2026
·
Updated

Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key material and/or cryptographic outcomes via induced transient faults that corrupt or redirect seed/pointer values during Keccak-based expansion.

This issue affects wolfSSL (wolfCrypt): commit hash d86575c766e6e67ef93545fa69c04d6eb49400c6.

Affected Software

2 affected components
wolfSSL wolfCrypt=d86575c766e6e67ef93545fa69c04d6eb49400c6
wolfSSL wolfssl>=5.8.2<5.9.0

Event History

Mar 19, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-3503?

The severity of CVE-2026-3503 is significant due to its ability to allow physical attackers to compromise cryptographic keys and outcomes.

2

How do I fix CVE-2026-3503?

To mitigate CVE-2026-3503, upgrade to the latest version of wolfCrypt that addresses the fault injection vulnerabilities.

3

What impact does CVE-2026-3503 have on ARM Cortex-M microcontrollers?

CVE-2026-3503 can lead to compromised key material and false cryptographic outcomes on ARM Cortex-M microcontrollers.

4

Who is affected by CVE-2026-3503?

CVE-2026-3503 affects users of wolfCrypt in the specified version on ARM Cortex-M microcontrollers.

5

What is the nature of the attack described in CVE-2026-3503?

CVE-2026-3503 involves a fault injection attack enabled by induced transient faults on the cryptographic implementations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203