Multiple constant-time implementations in wolfSSL before...
Low severity
Unreviewed
Published
Dec 11, 2025
to the GitHub Advisory Database
•
Updated Dec 11, 2025
Description
Published by the National Vulnerability Database
Dec 11, 2025
Published to the GitHub Advisory Database
Dec 11, 2025
Last updated
Dec 11, 2025
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
References