Wolfssl · Wolfssl · CVE-2026-3579
**Name of the Vulnerable Software and Affected Versions**
wolfSSL version 5.8.4
**Description**
wolfSSL version 5.8.4 on RISC-V RV32I architectures does not have a constant-time software implementation for 64-bit multiplication. The compiler-inserted ` muldi3` subroutine executes in variable time depending on the operand values. This impacts several SP math functions, including `sp 256 mul 9` and `sp 256 sqr 9`, resulting in a timing side-channel that could reveal sensitive cryptographic data.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.