Home
LOW: 1.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:NDefault status
unaffected
Any version before 5.8.4
affected
Description
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
Problem types
CWE-203 Observable Discrepancy
Product status
Any version before 5.8.4
Credits
Jing Liu
Zhiyuan Zhang
LUCÍA MARTÍNEZ GAVIER
Gilles Barthe
Marcel Böhme
References
github.com/wolfSSL/wolfssl/pull/9148
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.