Debian Wolfssl vulnerabilities
85 known vulnerabilities affecting debian/wolfssl.
Total CVEs
85
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH22MEDIUM35LOW18
Vulnerabilities
Page 3 of 5
CVE-2019-15651P4CRITICALCVSS 9.8fixed in wolfssl 4.1.0+dfsg-2 (bookworm)2019
CVE-2019-15651 [CRITICAL] CVE-2019-15651: wolfssl - wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions...
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.
Scope: local
bookworm: resolved (fixed in 4.1.0+dfsg-2)
bullseye: resolved (fixed in 4.1.0+dfsg-2)
forky: resolved (fixed in 4.1.0+dfsg-2)
sid: resolved (fixed in
debian
CVE-2015-6925P4HIGHCVSS 7.5fixed in wolfssl 3.9.10+dfsg-1 (bookworm)2015
CVE-2015-6925 [HIGH] CVE-2015-6925: wolfssl - wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial...
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
Scope: local
bookworm: resolved (fixed in 3.9.10+dfsg-1)
bullseye: resolved (fixed in 3.9.10+dfsg-1)
forky: resolved (fixed in 3.9.10+dfsg-1)
sid: resolved (fixed in 3.9.10+dfsg-
debian
CVE-2020-12457P3HIGHCVSS 7.5fixed in wolfssl 4.5.0+dfsg-1 (bookworm)2020
CVE-2020-12457 [HIGH] CVE-2020-12457: wolfssl - An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher...
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server becomes stuck in the ProcessReply() loop, i.e., a denial of service.
Scope: local
bookworm: resolved (fixed in 4.5.0+dfsg-1)
bull
debian
CVE-2022-34293P4HIGHCVSS 7.5fixed in wolfssl 5.5.3-1 (bookworm)2022
CVE-2022-34293 [HIGH] CVE-2022-34293: wolfssl - wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DT...
wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.
Scope: local
bookworm: resolved (fixed in 5.5.3-1)
bullseye: open
forky: resolved (fixed in 5.5.3-1)
sid: resolved (fixed in 5.5.3-1)
trixie: resolved (fixed in 5.5.3-1)
debian
CVE-2017-8855P4HIGHCVSS 7.5fixed in wolfssl 3.12.0+dfsg-1 (bookworm)2017
CVE-2017-8855 [HIGH] CVE-2017-8855: wolfssl - wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH ...
wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.
Scope: local
bookworm: resolved (fixed in 3.12.0+dfsg-1)
bullseye: resolved (fixed in 3.12.0+dfsg-1)
forky: resolved (fixed in 3.12.0+dfsg-1)
sid: resolved (fixed in 3.12.0+dfsg-1)
trixie: resolved (fixed in 3.12.0+dfsg-1)
debian
CVE-2025-11933P3LOWCVSS 2.3fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-11933 [LOW] CVE-2025-11933: wolfssl - Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 ...
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.8.4-1)
sid: resolved (fixed in 5.8.4-
debian
CVE-2025-11936P4MEDIUMCVSS 6.3fixed in wolfssl 5.8.4-1 (forky)2025
CVE-2025-11936 [MEDIUM] CVE-2025-11936: wolfssl - Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2...
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
S
debian
CVE-2026-0819P4LOWCVSS 2.2fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-0819 [LOW] CVE-2026-0819: wolfssl - A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encod...
A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to EncodeAttributes() instead of the remaining available space in the fixed-size signedAttribs[7] array. When an application se
debian
CVE-2023-6935P4LOWCVSS 5.9fixed in wolfssl 5.6.6-1.2 (forky)2023
CVE-2023-6935 [MEDIUM] CVE-2023-6935: wolfssl - wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new v...
wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define “WOLFSSL_STATIC_RSA” enables static RSA cipher suites, which is not recommended, and has been disabled by default since wolfSSL 3.6.
debian
CVE-2026-3579P4LOWCVSS 2.1fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-3579 [LOW] CVE-2026-3579: wolfssl - wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software imple...
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This affects multiple SP math functions (sp_256_mul_9, sp_256_sqr_9, etc.), leading to a timing side-channel that may expose sensitive cryptographic data.
Scope:
debian
CVE-2022-38153P4MEDIUMCVSS 5.9fixed in wolfssl 5.5.3-1 (bookworm)2022
CVE-2022-38153 [MEDIUM] CVE-2022-38153: wolfssl - An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is...
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attacker injects a large ticket (more than 256 bytes) into a NewSessionTicket message in a TLS 1.2 handshake, and the client has a n
debian
CVE-2026-1005P4LOWCVSS 2.1fixed in wolfssl 5.9.0-0.1 (forky)2026
CVE-2026-1005 [LOW] CVE-2026-1005: wolfssl - Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause...
Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing heap buffer over
debian
CVE-2022-25638P4MEDIUMCVSS 6.5fixed in wolfssl 5.2.0-1 (bookworm)2022
CVE-2022-25638 [MEDIUM] CVE-2022-25638: wolfssl - In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted...
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.
Scope: local
bookworm: resolved (fixed in 5.2.0-1)
bullseye: resolved (fixed in 4.6.0+p1-0+deb11u1)
forky: resolved (
debian
CVE-2018-16870P4MEDIUMCVSS 5.9fixed in wolfssl 4.1.0+dfsg-1 (bookworm)2018
CVE-2018-16870 [MEDIUM] CVE-2018-16870: wolfssl - It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bl...
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
Scope: local
bookworm: resolved (fixed in 4.1.0+dfsg-1)
bullseye: resolved (fixed in 4.1.0+dfsg-1)
forky: resolved (fixed in 4.1.0+dfsg-1)
sid: resolved (fixed in 4.1.0+dfsg-1)
trix
debian
CVE-2019-14317P4MEDIUMCVSS 5.3fixed in wolfssl 4.2.0+dfsg-1 (bookworm)2019
CVE-2019-14317 [MEDIUM] CVE-2019-14317: wolfssl - wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate bias...
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c fixes two bits of the generated nonces.
Scope: local
bookworm: resolved (fixed in 4.2.0+dfsg-1)
bullseye: resolved
debian
CVE-2024-5288P4MEDIUMCVSS 5.1fixed in wolfssl 5.7.2-0.1 (forky)2024
CVE-2024-5288 [MEDIUM] CVE-2024-5288: wolfssl - An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhamm...
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success rate in a certain amount of connection requests can
debian
CVE-2014-2903P4MEDIUMCVSS 5.9fixed in wolfssl 3.4.8+dfsg-1 (bookworm)2014
CVE-2014-2903 [MEDIUM] CVE-2014-2903: wolfssl - CyaSSL does not check the key usage extension in leaf certificates, which allows...
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.
Scope: local
bookworm: resolved (fixed in 3.4.8+dfsg-1)
bullseye: resolved (fixed in 3.4.8+dfsg-1)
forky: resolved (fixed in 3.4.8+dfsg-1)
sid: resolved (fixed in 3.4.8+dfs
debian
CVE-2024-5814P4MEDIUMCVSS 5.1fixed in wolfssl 5.7.2-0.1 (forky)2024
CVE-2024-5814 [MEDIUM] CVE-2024-5814: wolfssl - A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to...
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500
Scope: local
bookworm: open
bullseye: open
forky: resolved
debian
CVE-2020-15309P4HIGHCVSS 7.0fixed in wolfssl 4.5.0+dfsg-1 (bookworm)2020
CVE-2020-15309 [HIGH] CVE-2020-15309: wolfssl - An issue was discovered in wolfSSL before 4.5.0, when single precision is not em...
An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).
Scope: local
bookworm: resolved (fi
debian
CVE-2021-44718P4MEDIUMCVSS 5.9fixed in wolfssl 5.1.1-1 (bookworm)2021
CVE-2021-44718 [MEDIUM] CVE-2021-44718: wolfssl - wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infini...
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.
Scope: local
bookworm: resolved (fixed in 5.1.1-1)
bullseye: resolved (fixe
debian