CVE-2025-11931: Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt
Published Nov 21, 2025
·Updated
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt
Affected Software
1 affected component
wolfSSL wolfssl=5.8.4
Remediation
Patch Available
Event History
Nov 21, 2025
CVE Published
via MITRE·10:57 PM
Data Sourced
via MITRE·10:57 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 25, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11931?
CVE-2025-11931 has been rated as a medium severity vulnerability due to potential exploitation leading to out-of-bounds access.
2
How do I fix CVE-2025-11931?
To fix CVE-2025-11931, update to wolfSSL version 5.8.5 or later where the vulnerability is patched.
3
What software is affected by CVE-2025-11931?
CVE-2025-11931 specifically affects wolfSSL version 5.8.4.
4
What type of vulnerability is CVE-2025-11931?
CVE-2025-11931 is an integer underflow vulnerability that leads to out-of-bounds access.
5
What is the impact of CVE-2025-11931?
The impact of CVE-2025-11931 includes potential arbitrary code execution via out-of-bounds memory access.