Timing Discrepancy Vulnerability in AMD Vitis Libraries ECDSA secp256k1 Component
CVE-2026-43606
7.7HIGH
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-43606?
A timing discrepancy vulnerability exists in the ECDSA secp256k1 component of the AMD Vitis Libraries, which could enable local attackers to exploit the timing of operations. This flaw may lead to potential timing analysis or electromagnetic emanation attacks, ultimately compromising the confidentiality and integrity of sensitive cryptographic keys. Users are advised to review the security bulletin and apply necessary updates to safeguard against these risks.
Affected Version(s)
Vitis™ Libraries - Security Module 2026.1
Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows 2026.1