Executive brief
wolfSSL is a security library used to encrypt communications for embedded devices and cloud services. A technical error in how the library handles certain mathematical calculations for X25519 cryptography could result in incorrect shared secrets being generated. This could lead to failed connections or potential disruptions in secure communications between devices.
Technical details
A vulnerability exists in the X25519 x86_64 assembly implementation (x64 and AVX2 routines) where the most significant bit is not cleared during the final modular reduction. Specifically, the final carry-propagation chains can overflow into the top bit, and because the high limb is not subsequently masked, the 255-bit field element remains in a non-canonical form. This results in incorrect scalar multiplication and the generation of incorrect shared secrets. The issue affects wolfSSL versions 5.6.4 through 5.9.1 and was addressed by adding proper masking to the last word in the assembly code.
Affected products
- wolfSSL wolfSSL 5.6.4 to 5.9.1
Timeline
- 2026-05-27: other: Pull request submitted to wolfSSL GitHub
- 2026-06-03: patched: Fix merged into master branch
- 2026-06-25: disclosed: CVE published to NVD