A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Patch name: fdec3c90a15447bd538641d85e5a3e3ac981011d. To fix this issue, it is recommended to deploy a patch.
Metrics
Affected Vendors & Products
References
History
Sun, 08 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Patch name: fdec3c90a15447bd538641d85e5a3e3ac981011d. To fix this issue, it is recommended to deploy a patch. | |
| Title | mkj Dropbear S Range Check curve25519.c unpackneg signature verification | |
| Weaknesses | CWE-345 CWE-347 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-08T05:02:11.136Z
Reserved: 2026-03-07T09:05:33.842Z
Link: CVE-2026-3706
No data.
Status : Received
Published: 2026-03-08T05:16:31.847
Modified: 2026-03-08T05:16:31.847
Link: CVE-2026-3706
No data.
OpenCVE Enrichment
No data.