Timing Side-Channel Vulnerability in wolfSSL
CVE-2025-13912
1LOW
What is CVE-2025-13912?
wolfSSL versions prior to 5.8.4 exhibit a security vulnerability where multiple constant-time implementations may be inadvertently altered by LLVM optimizations. This alteration can transform them into non-constant-time binaries, leading to timing discrepancies that attackers can exploit. Such discrepancies potentially enable timing side-channel attacks, allowing unauthorized data exposure.
Affected Version(s)
wolfSSL 0 < 5.8.4
References
CVSS V4
Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jing Liu
Zhiyuan Zhang
LUCĂŤA MARTĂŤNEZ GAVIER
Gilles Barthe
Marcel Böhme
