CVE-2025-27587
OpenSSL vulnerability analysis and mitigation

Overview

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, discovered and reported in 2024. This disputed vulnerability (CVE-2025-27587) affects the EVP_DigestSign API implementation specifically on PowerPC systems (CVE Details, NVD).

Technical details

The vulnerability exploits a timing side-channel in the P-364 curve implementation. Attackers can measure the time of signing random messages using the EVP_DigestSign API (Init, Update, and Final) to extract the K value (nonce) from signatures. By analyzing the bit size of the extracted nonce and comparing signing times between full-sized nonces and smaller nonces using statistical tests, attackers can determine a dependency between the bit size of K and the size of the side channel (GitHub Issue).

Impact

If successfully exploited, the vulnerability allows attackers to extract the private key from signatures. However, the timing signal is extremely small and requires the attacking process to run on the same physical system as the target, significantly limiting the practical impact (NVD).

Mitigation and workarounds

The vulnerability specifically affects PowerPC architecture implementations. Users on other architectures are not impacted. For affected systems, no official mitigation has been published as the vulnerability is disputed and considered outside OpenSSL's threat model (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related OpenSSL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-53159CRITICAL9.1
  • RustRust
  • rust-src
NoYesJul 28, 2025
CVE-2025-4575MEDIUM6.5
  • OpenSSLOpenSSL
  • openssl
NoYesMay 22, 2025
CVE-2024-12797MEDIUM6.3
  • PythonPython
  • datadog-agent
NoYesFeb 11, 2025
CVE-2025-27587MEDIUM5.3
  • OpenSSLOpenSSL
  • libopenssl-3-devel-32bit
NoYesJun 16, 2025
CVE-2025-3416LOW3.7
  • OpenSSLOpenSSL
  • icecat-langpacks
NoYesApr 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management