CVE-2025-11932: Timing Side-Channel in PSK Binder Verification
Published Nov 21, 2025
·Updated
The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder
Other sources
Timing Side-Channel in PSK Binder Verification
— Microsoft
Affected Software
1 affected component
wolfSSL wolfssl=5.8.2
Remediation
Patch Available
Event History
Nov 21, 2025
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 25, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11932?
CVE-2025-11932 has been assigned a severity rating that indicates a potential information leak via a timing side-channel attack.
2
How do I fix CVE-2025-11932?
To fix CVE-2025-11932, update to version 5.8.3 or later of wolfSSL.
3
What versions of wolfSSL are affected by CVE-2025-11932?
CVE-2025-11932 affects wolfSSL version 5.8.2.
4
What type of attack does CVE-2025-11932 enable?
CVE-2025-11932 could potentially allow an attacker to exploit a timing side-channel to leak information.
5
Is CVE-2025-11932 specific to a certain implementation?
Yes, CVE-2025-11932 specifically affects the wolfSSL implementation of TLS 1.3.