CVE-2026-3503: Fault injection attack with ML-DSA and ML-KEM on ARM
Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key material and/or cryptographic outcomes via induced transient faults that corrupt or redirect seed/pointer values during Keccak-based expansion.
This issue affects wolfSSL (wolfCrypt): commit hash d86575c766e6e67ef93545fa69c04d6eb49400c6.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3503?
The severity of CVE-2026-3503 is significant due to its ability to allow physical attackers to compromise cryptographic keys and outcomes.
How do I fix CVE-2026-3503?
To mitigate CVE-2026-3503, upgrade to the latest version of wolfCrypt that addresses the fault injection vulnerabilities.
What impact does CVE-2026-3503 have on ARM Cortex-M microcontrollers?
CVE-2026-3503 can lead to compromised key material and false cryptographic outcomes on ARM Cortex-M microcontrollers.
Who is affected by CVE-2026-3503?
CVE-2026-3503 affects users of wolfCrypt in the specified version on ARM Cortex-M microcontrollers.
What is the nature of the attack described in CVE-2026-3503?
CVE-2026-3503 involves a fault injection attack enabled by induced transient faults on the cryptographic implementations.