ECHO-3213-e8f7-97f9

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-3213-e8f7-97f9.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-3213-e8f7-97f9
Upstream
Withdrawn
2025-08-03T16:59:06Z
Published
2025-09-15T01:12:08Z
Modified
2026-09-15T03:33:39Z
Summary
A side channel attack (Minerva). The problem is specific to the powerpc architecture. The fix was also exclusively applied to it. https://security-tracker.debian.org/tracker/CVE-2025-27587 https://github.com/openssl/openssl/issues/24253 https://minerva.crocs.fi.muni.cz/ There is a fix for later versions but we don't need to apply it for now. https://github.com/openssl/openssl/commit/85cabd94958303859b1551364a609d4ff40b67a5 In addition to only being applicable to powerpc, openssl don't consider it to be covered in their security policy, since an attacker needs additional code running on the same machine (which is not good enough for us).
Details
References

Affected packages

Echo / openssl

Package

Name
openssl
Purl
pkg:deb/echo/openssl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.0

Database specific

source
"https://advisory.echohq.com/osv/ECHO-3213-e8f7-97f9.json"