CVE-2025-22866

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Feb 6, 2025
Updated: Feb 21, 2025

Summary

CVE-2025-22866 is a vulnerability affecting the ppc64le architecture that stems from the implementation of a variable time instruction in an internal function. This issue results in a leakage of a small number of bits of secret scalars. However, the impact of this leakage is considered limited, as it is not believed to enable the recovery of private keys when P-256 is used in standard protocols.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share