Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.
In situations where an attacker receives automated notification of the ...
Last updated 18 August 2025
Last updated 24 July 2024
If client authentication is used, then a server can crash with a segmentation fault in the event of a DHE ciphersuite being selected and a zero length ClientKeyExchange (CKE) message being sent by the client. This could be exploited in a denial of service attack.
This issue affects OpenSSL version 1.0.2, and is fixed in version 1.0.2a.
Acknowledgements:
Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Matt Caswell of the OpenSSL development team as the original reporter.