Potential non-constant time compiled code with Clang LLVM
Vulnerability Description
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13912
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Jing Liu
- Zhiyuan Zhang
- LUCÍA MARTÍNEZ GAVIER
- Gilles Barthe
- Marcel Böhme
References
More from wolfSSL
View All →Affected Vendor
wolfSSL
View all reports →