CVE-2025-11931

Name
CVE-2025-11931
Description
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
facts@wolfssl.com https://github.com/wolfSSL/wolfssl/pull/9223

Match rules

CPE URI Source package Min version Max version
wolfssl == 5.8.4 == None
cpe:2.3:a:wolfssl:wolfssl:5.8.4:*:*:*:*:*:*:* wolfssl == None == 5.8.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wolfssl edge-community 5.8.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.7.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.6.6-r0 None possibly vulnerable
wolfssl edge-community 5.6.2-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.3-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.5.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl edge-community 5.4.0-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.6-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
wolfssl 3.22-community 5.7.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.7.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.6-r0 None possibly vulnerable
wolfssl 3.22-community 5.6.2-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.3-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.1-r0 None possibly vulnerable
wolfssl 3.22-community 5.5.0-r0 None possibly vulnerable
wolfssl 3.22-community 5.4.0-r0 None possibly vulnerable