cbcvebase.

Debian Wolfssl vulnerabilities

85 known vulnerabilities affecting debian/wolfssl.

Total CVEs
85
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH22MEDIUM35LOW18

Vulnerabilities

Page 2 of 5
CVE-2022-23408P3CRITICALCVSS 9.1fixed in wolfssl 5.1.1-1 (bookworm)2022
CVE-2022-23408 [CRITICAL] CVE-2022-23408: wolfssl - wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This a... wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c. Scope: local bookworm: resolved (fixed in 5.1.1-1) bullseye: resolved forky: resolved (fixed in 5.1.1-
debian
CVE-2025-11931P3LOWCVSS 2.1fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-11931 [LOW] CVE-2025-11931: wolfssl - Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. T... Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 5.8.4-1) sid: resolved (fixed in 5.8.4-1) trixi
debian
CVE-2024-0901P3HIGHCVSS 7.5fixed in wolfssl 5.7.0-0.3 (forky)2024
CVE-2024-0901 [HIGH] CVE-2024-0901: wolfssl - Remotely executed SEGV and out of bounds read allows malicious packet sender to ... Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 5.7.0-0.3) sid: resolved (fixed in 5.7.0-0.3) trixie: resolved (fixed in 5.7.0-0.3)
debian
CVE-2020-11713P3HIGHCVSS 7.5fixed in wolfssl 4.4.0+dfsg-1 (bookworm)2020
CVE-2020-11713 [HIGH] CVE-2020-11713: wolfssl - wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properl... wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks. Scope: local bookworm: resolved (fixed in 4.4.0+dfsg-1) bullseye: resolved (fixed in 4.4.0+dfsg-1) forky: resolved (fixed in 4.4.0+dfsg-1) sid: resolved (fixed in 4.4.0+dfsg-1) trixie: resolved (fixed in 4.4.0+dfsg-1)
debian
CVE-2022-25640P3HIGHCVSS 7.5fixed in wolfssl 5.2.0-1 (bookworm)2022
CVE-2022-25640 [HIGH] CVE-2022-25640: wolfssl - In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement ... In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate. Scope: local bookworm: resolved (fixed in 5.2.0-1) bullseye: resolved (fixed in 4.6.0+p1-0+deb11u1) forky: resolved (fixed in 5.2.0-1) sid: resolved (fi
debian
CVE-2026-2645P3MEDIUMCVSS 5.5fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-2645 [MEDIUM] CVE-2026-2645: wolfssl - In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state m... In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange message had been received. This issue affects wolfSSL before 5.8.4 (wolfSSL 5.8.2 and earlier is vulnerable, 5.8.4 is not vulnerable). In 5.8.4 wolfSSL would detect the i
debian
CVE-2024-5991P3CRITICALCVSS 10.0fixed in wolfssl 5.7.2-0.1 (forky)2024
CVE-2024-5991 [CRITICAL] CVE-2024-5991: wolfssl - In function MatchDomainName(), input param str is treated as a NULL terminated s... In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a caller was attempting to do a name check on a non-NULL terminated buffer, the code would r
debian
CVE-2025-12888P3LOWCVSS 1.0fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-12888 [LOW] CVE-2025-12888: wolfssl - Vulnerability in X25519 constant-time cryptographic implementations due to timin... Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa. Scope: local book
debian
CVE-2014-2904P3HIGHCVSS 7.5fixed in wolfssl 3.4.8+dfsg-1 (bookworm)2014
CVE-2014-2904 [HIGH] CVE-2014-2904: wolfssl - wolfssl before 3.2.0 has a server certificate that is not properly authorized fo... wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. Scope: local bookworm: resolved (fixed in 3.4.8+dfsg-1) bullseye: resolved (fixed in 3.4.8+dfsg-1) forky: resolved (fixed in 3.4.8+dfsg-1) sid: resolved (fixed in 3.4.8+dfsg-1) trixie: resolved (fixed in 3.4.8+dfsg-1)
debian
CVE-2022-38152P3HIGHCVSS 7.5fixed in wolfssl 5.5.3-1 (bookworm)2022
CVE-2022-38152 [HIGH] CVE-2022-38152: wolfssl - An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects ... An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the server reuses the previous session structure (struct
debian
CVE-2019-18840P3HIGHCVSS 7.5fixed in wolfssl 4.2.0+dfsg-3 (bookworm)2019
CVE-2019-18840 [HIGH] CVE-2019-18840: wolfssl - In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory acces... In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an inv
debian
CVE-2021-3336P3HIGHCVSS 8.1fixed in wolfssl 4.6.0-3 (bookworm)2021
CVE-2021-3336 [HIGH] CVE-2021-3336: wolfssl - DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease proce... DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The client side is affected because man-in-the-middle attackers can impersonate TLS 1.3 servers. Scope: local bookworm: resolved (fixed in 4.6.0-3) bullseye:
debian
CVE-2019-16748P3CRITICALCVSS 9.8fixed in wolfssl 4.2.0+dfsg-1 (bookworm)2019
CVE-2019-16748 [CRITICAL] CVE-2019-16748: wolfssl - In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in ... In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c. Scope: local bookworm: resolved (fixed in 4.2.0+dfsg-1) bullseye: resolved (fixed in 4.2.0+dfsg-1) forky: resolved (fixed i
debian
CVE-2019-19962P3HIGHCVSS 7.5fixed in wolfssl 4.3.0+dfsg-1 (bookworm)2019
CVE-2019-19962 [HIGH] CVE-2019-19962: wolfssl - wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fa... wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. Scope: local bookworm: resolved (fixed in 4.3.0+dfsg-1) bullseye: resolved (fixed in 4.3.0+dfsg-1) forky: resolved (fixed in 4.3.0+dfsg-1) sid: resolved (fixed in 4.3.0+dfsg-1) trixie: resolved (fixed in 4.3.0+dfsg-1)
debian
CVE-2026-3547P3HIGHCVSS 7.5fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-3547 [HIGH] CVE-2026-3547: wolfssl - Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 a... Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is en
debian
CVE-2015-7744P3MEDIUMCVSS 5.9fixed in wolfssl 3.9.10+dfsg-1 (bookworm)2015
CVE-2015-7744 [MEDIUM] CVE-2015-7744: wolfssl - wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associate... wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack. Scope: local bookworm: resolved (
debian
CVE-2014-2901P3HIGHCVSS 7.5fixed in wolfssl 3.4.8+dfsg-1 (bookworm)2014
CVE-2014-2901 [HIGH] CVE-2014-2901: wolfssl - wolfssl before 3.2.0 does not properly issue certificates for a server's hostnam... wolfssl before 3.2.0 does not properly issue certificates for a server's hostname. Scope: local bookworm: resolved (fixed in 3.4.8+dfsg-1) bullseye: resolved (fixed in 3.4.8+dfsg-1) forky: resolved (fixed in 3.4.8+dfsg-1) sid: resolved (fixed in 3.4.8+dfsg-1) trixie: resolved (fixed in 3.4.8+dfsg-1)
debian
CVE-2020-24613P3MEDIUMCVSS 6.8fixed in wolfssl 4.5.0+dfsg-1 (bookworm)2020
CVE-2020-24613 [MEDIUM] CVE-2020-24613: wolfssl - wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, w... wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between cl
debian
CVE-2017-8854P3HIGHCVSS 7.8fixed in wolfssl 3.10.2+dfsg-1 (bookworm)2017
CVE-2017-8854 [HIGH] CVE-2017-8854: wolfssl - wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH... wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file. Scope: local bookworm: resolved (fixed in 3.10.2+dfsg-1) bullseye: resolved (fixed in 3.10.2+dfsg-1) forky: resolved (fixed in 3.10.2+dfsg-1) sid: resolved (fixed in 3.10.2+dfsg-1) trixie: resolved (fixed in 3.1
debian
CVE-2014-2902P3HIGHCVSS 7.5fixed in wolfssl 3.4.8+dfsg-1 (bookworm)2014
CVE-2014-2902 [HIGH] CVE-2014-2902: wolfssl - wolfssl before 3.2.0 does not properly authorize CA certificate for signing othe... wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. Scope: local bookworm: resolved (fixed in 3.4.8+dfsg-1) bullseye: resolved (fixed in 3.4.8+dfsg-1) forky: resolved (fixed in 3.4.8+dfsg-1) sid: resolved (fixed in 3.4.8+dfsg-1) trixie: resolved (fixed in 3.4.8+dfsg-1)
debian
Debian Wolfssl vulnerabilities | cvebase