Skip to content

Conversation

@kareem-wolfssl
Copy link
Contributor

Description

Fixes zd#20543 zd#20544

Testing

Reporter to confirm fixes.

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@kareem-wolfssl kareem-wolfssl self-assigned this Sep 19, 2025
@philljj philljj self-requested a review September 22, 2025 19:02
@SparkiDev SparkiDev self-assigned this Sep 22, 2025
@SparkiDev SparkiDev merged commit e497d28 into wolfSSL:master Sep 22, 2025
252 checks passed
kraj pushed a commit to YoeDistro/meta-openembedded that referenced this pull request Dec 23, 2025
NVD claims that WolfSSL 5.8.4 is affected by both of these vulnerabilities,
however actually both have been fixed in that version.

CVE-2025-11931: NVD[1] references [2] PR as a patch, which was merged in [3].
CVE-2025-12889: NVD[4] referenced [5] PR as a patch, which was merged in [6].

[1]: https://nvd.nist.gov/vuln/detail/CVE-2025-11931
[2]: wolfSSL/wolfssl#9223
[3]: wolfSSL/wolfssl@e497d28
[4]: https://nvd.nist.gov/vuln/detail/CVE-2025-12889
[5]: wolfSSL/wolfssl#9395
[6]: wolfSSL/wolfssl@2db1c7a

Signed-off-by: Gyorgy Sarvari <[email protected]>
Signed-off-by: Khem Raj <[email protected]>
kraj pushed a commit to YoeDistro/meta-openembedded that referenced this pull request Dec 24, 2025
NVD claims that WolfSSL 5.8.4 is affected by both of these vulnerabilities,
however actually both have been fixed in that version.

CVE-2025-11931: NVD[1] references [2] PR as a patch, which was merged in [3].
CVE-2025-12889: NVD[4] referenced [5] PR as a patch, which was merged in [6].

[1]: https://nvd.nist.gov/vuln/detail/CVE-2025-11931
[2]: wolfSSL/wolfssl#9223
[3]: wolfSSL/wolfssl@e497d28
[4]: https://nvd.nist.gov/vuln/detail/CVE-2025-12889
[5]: wolfSSL/wolfssl#9395
[6]: wolfSSL/wolfssl@2db1c7a

Signed-off-by: Gyorgy Sarvari <[email protected]>
Signed-off-by: Khem Raj <[email protected]>
kraj pushed a commit to YoeDistro/meta-openembedded that referenced this pull request Dec 24, 2025
NVD claims that WolfSSL 5.8.4 is affected by both of these vulnerabilities,
however actually both have been fixed in that version.

CVE-2025-11931: NVD[1] references [2] PR as a patch, which was merged in [3].
CVE-2025-12889: NVD[4] referenced [5] PR as a patch, which was merged in [6].

[1]: https://nvd.nist.gov/vuln/detail/CVE-2025-11931
[2]: wolfSSL/wolfssl#9223
[3]: wolfSSL/wolfssl@e497d28
[4]: https://nvd.nist.gov/vuln/detail/CVE-2025-12889
[5]: wolfSSL/wolfssl#9395
[6]: wolfSSL/wolfssl@2db1c7a

Signed-off-by: Gyorgy Sarvari <[email protected]>
Signed-off-by: Khem Raj <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants