Net::Dropbear LibTomCrypt Vulnerability in ECDSA Key Extraction

Vulnerability

A vulnerability exists in Net::Dropbear versions prior to 0.14, specifically in the handling of LibTomCrypt. This issue allows for a memory-cache side-channel attack on ECDSA signatures, known as the Return Of the Hidden Number Problem (ROHNP). An attacker can exploit this vulnerability to extract ECDSA keys, given access to the local machine or a different virtual machine on the same physical host.

Impact

Exploitation of this vulnerability allows for the extraction of ECDSA private keys, which can lead to the forgery of signatures or public certificates.

Reproduction

The vulnerability can be reproduced by using a version of Net::Dropbear prior to 0.14 that includes LibTomCrypt version 1.18.1 or earlier. The attack involves accessing ECDSA signatures in a way that leverages the memory-cache timing differences to extract private key information.

Remediation

Users can upgrade to Net::Dropbear version 0.14 or later, which addresses this vulnerability by including a patched version of LibTomCrypt that is not susceptible to this type of side-channel attack.

Added: Apr 21, 2026, 4:38 PM
Updated: Apr 21, 2026, 4:38 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
1.9
exploitability
5.7
remediation
7.7
relevance
6.4
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.