CVE-2026-87737
Linux Debian Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-87737 is a timing side-channel vulnerability in the mirage-crypto-ec package for OCaml, affecting all versions before 2.4.0. The flaw exists in NIST elliptic-curve scalar multiplication, where the time required for a lookup operation can vary based on a secret value, potentially leaking cryptographic key material. It was published on September 9, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (GitHub Advisory, Feedly).

Dettagli tecnici

The vulnerability is classified as CWE-208 (Observable Timing Discrepancy), arising from non-constant-time execution during table lookups in NIST elliptic-curve scalar multiplication within the mirage-crypto-ec library. An unauthenticated remote attacker can exploit this by repeatedly invoking cryptographic operations and measuring response times to statistically infer secret scalar values — a classic timing side-channel attack. No special privileges or user interaction are required, though exploitation requires high attack complexity due to the statistical nature of timing analysis. The vulnerability is also mapped to CAPEC-462 (Cross-Domain Search Timing) (GitHub Advisory, OSV).

Impatto

Successful exploitation allows an unauthenticated network attacker to extract secret cryptographic key material from applications using the vulnerable mirage-crypto-ec library through timing analysis of elliptic-curve operations. The impact is limited to confidentiality — integrity and availability are not affected — but exposure of private keys could enable impersonation, decryption of protected communications, or compromise of TLS sessions depending on how the library is used in the target application (GitHub Advisory, Feedly).

Sfruttabilità

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a very low probability of near-term exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity, as it depends on the ability to perform precise, repeated timing measurements of cryptographic operations over a network.

Mitigazione e soluzioni alternative

The primary remediation is to upgrade the mirage-crypto-ec package to version 2.4.0 or later, which addresses the non-constant-time lookup issue in NIST elliptic-curve scalar multiplication (GitHub Advisory). If immediate patching is not possible, consider implementing network-level mitigations such as rate limiting or jitter on cryptographic operation responses to reduce timing measurement precision. Applications relying on this library for TLS or key exchange should be prioritized for patching given the potential for key material exposure.

Reazioni della comunità

The vulnerability received limited public attention at the time of disclosure, with automated CVE tracking services (VulDB, CVEFeed, cve.report) and a Bluesky post from a CVE monitoring account being the primary sources of coverage (Feedly). No notable researcher commentary or vendor statements beyond the GitHub Advisory Database entry have been identified.

Risorse aggiuntive

Stato della correzione della distribuzione Linux

Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.

Debian

Fisso

bookworm

ocaml-mirage-crypto

Interessati

sid

ocaml-mirage-crypto: 2.4.0-1

Fisso

trixie

ocaml-mirage-crypto

Interessati

Ubuntu

Sconosciuto

devel

ocaml-mirage-crypto

Sconosciuto

jammy

ocaml-mirage-crypto

Sconosciuto

jammy (esm-apps)

ocaml-mirage-crypto

Sconosciuto

noble

ocaml-mirage-crypto

Sconosciuto

noble (esm-apps)

ocaml-mirage-crypto

Sconosciuto

resolute

ocaml-mirage-crypto

Sconosciuto

resolute (esm-apps)

ocaml-mirage-crypto

Sconosciuto

FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato Linux Debian Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-87733MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87732MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87737MEDIUM5.9
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87736MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87735MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità