Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21941 | In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature. While the side-channel attack on extracting a private key would be very difficult to execute in practice, enabling blinding provides an additional layer of protection for devices that may be more susceptible to physical access or side-channel observation. |
Wed, 03 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:wolfssl:wolfssl:5.8.2:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 21 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-385 | |
| Metrics |
ssvc
|
Fri, 18 Jul 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature. While the side-channel attack on extracting a private key would be very difficult to execute in practice, enabling blinding provides an additional layer of protection for devices that may be more susceptible to physical access or side-channel observation. | |
| Title | Curve25519 Blinding | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2025-07-21T15:05:59.222Z
Reserved: 2025-07-09T16:44:18.737Z
Link: CVE-2025-7396
Updated: 2025-07-21T15:05:35.929Z
Status : Analyzed
Published: 2025-07-18T23:15:23.797
Modified: 2025-12-03T15:25:26.673
Link: CVE-2025-7396
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:17:07Z
EUVD