{"id":"ECHO-3213-e8f7-97f9","summary":"A side channel attack (Minerva). The problem is specific to the powerpc architecture. The fix was also\nexclusively applied to it.\nhttps://security-tracker.debian.org/tracker/CVE-2025-27587\nhttps://github.com/openssl/openssl/issues/24253\nhttps://minerva.crocs.fi.muni.cz/\nThere is a fix for later versions but we don't need to apply it for now.\nhttps://github.com/openssl/openssl/commit/85cabd94958303859b1551364a609d4ff40b67a5\nIn addition to only being applicable to powerpc, openssl don't consider it to be covered in their\nsecurity policy, since an attacker needs additional code running on the same machine (which is not\ngood enough for us).\n","modified":"2026-09-15T03:33:39.433520542Z","published":"2025-09-15T01:12:08.183082Z","withdrawn":"2025-08-03T16:59:06.349Z","upstream":["CVE-2025-27587"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-27587"}],"affected":[{"package":{"name":"openssl","ecosystem":"Echo","purl":"pkg:deb/echo/openssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-3213-e8f7-97f9.json"}}],"schema_version":"1.9.0"}