Timing Side-Channel Vulnerability in wolfSSL
CVE-2025-13912

1LOW

Key Information:

Vendor

Wolfssl

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-13912?

wolfSSL versions prior to 5.8.4 exhibit a security vulnerability where multiple constant-time implementations may be inadvertently altered by LLVM optimizations. This alteration can transform them into non-constant-time binaries, leading to timing discrepancies that attackers can exploit. Such discrepancies potentially enable timing side-channel attacks, allowing unauthorized data exposure.

Affected Version(s)

wolfSSL 0 < 5.8.4

References

CVSS V4

Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jing Liu
Zhiyuan Zhang
LUCĂŤA MARTĂŤNEZ GAVIER
Gilles Barthe
Marcel Böhme
.
CVE-2025-13912 : Timing Side-Channel Vulnerability in wolfSSL