Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
History

Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
Title Potential non-constant time compiled code with Clang LLVM
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published: 2025-12-11T17:09:59.098Z

Updated: 2025-12-11T19:35:56.056Z

Reserved: 2025-12-02T17:27:26.760Z

Link: CVE-2025-13912

cve-icon Vulnrichment

Updated: 2025-12-11T19:19:10.485Z

cve-icon NVD

Status : Received

Published: 2025-12-11T18:16:19.067

Modified: 2025-12-11T18:16:19.067

Link: CVE-2025-13912

cve-icon Redhat

No data.