In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature. While the side-channel attack on extracting a private key would be very difficult to execute in practice, enabling blinding provides an additional layer of protection for devices that may be more susceptible to physical access or side-channel observation.
History

Mon, 21 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-385
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Jul 2025 23:00:00 +0000

Type Values Removed Values Added
Description In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assembly builds, and the small Curve25519 feature. While the side-channel attack on extracting a private key would be very difficult to execute in practice, enabling blinding provides an additional layer of protection for devices that may be more susceptible to physical access or side-channel observation.
Title Curve25519 Blinding
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: wolfSSL

Published: 2025-07-18T22:51:18.950Z

Updated: 2025-07-21T15:05:59.222Z

Reserved: 2025-07-09T16:44:18.737Z

Link: CVE-2025-7396

cve-icon Vulnrichment

Updated: 2025-07-21T15:05:35.929Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-18T23:15:23.797

Modified: 2025-07-22T13:06:07.260

Link: CVE-2025-7396

cve-icon Redhat

No data.