Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7582-g6xx-939j

Опубликовано: 11 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1

Описание

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

EPSS

Процентиль: 4%
0.00019
Низкий

1 Low

CVSS4

Дефекты

CWE-203

Связанные уязвимости

ubuntu
около 2 месяцев назад

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

nvd
около 2 месяцев назад

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

msrc
около 1 месяца назад

Potential non-constant time compiled code with Clang LLVM

debian
около 2 месяцев назад

Multiple constant-time implementations in wolfSSL before version 5.8.4 ...

EPSS

Процентиль: 4%
0.00019
Низкий

1 Low

CVSS4

Дефекты

CWE-203