PT-2025-30103 · Wolfssl+1 · Wolfssl+1
Allan Delautre
+2
·
Published
2025-07-18
·
Updated
2026-01-21
·
CVE-2025-7396
CVSS v4.0
5.6
Medium
| Vector | AV:P/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wolfSSL version 5.8.2
Description
In wolfSSL release 5.8.2, blinding support is enabled by default for Curve25519 in applicable builds. This feature provides an additional layer of protection against side-channel attacks aimed at extracting a private key, particularly for devices susceptible to physical access or observation. The blinding configure option applies only to the base C implementation of Curve25519 and is not available with ARM assembly builds, Intel assembly builds, or the small Curve25519 feature.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Wolfssl