Intel

AIKIDO-2026-10432

wolfSSL.wolfssl is vulnerable to Protection Mechanism Failure

Protection Mechanism FailureCVE-2026-3503 Published Mar 30, 2026

43

Medium Risk

This Affects:

C++wolfSSL.wolfssl
0.0.1 - 5.8.4
Fixed in 5.9.0
Are you affected? Scan for Free

TL;DR

ML-KEM and ML-DSA Keccak-based expansion on ARM Cortex-M can be influenced by transient faults that corrupt seeds or pointers during expansion, weakening post-quantum key material when an attacker can induce faults physically. The fix hardens the expansion path against such fault-induced misuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssl is vulnerable to Protection Mechanism Failure in versions 0.0.1 - 5.8.4.

How to fix this

Upgrade the wolfSSL.wolfssl library to the patch version.