The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
| Software | From | Fixed in |
|---|---|---|
| mariadb / mariadb | 10.0.0 | 10.0.28 |
| mariadb / mariadb | 10.1.0 | 10.1.19 |
| mariadb / mariadb | 5.5.0 | 5.5.53 |
| oracle / mysql | 5.5.0 | 5.5.52.x |
| oracle / mysql | 5.6.0 | 5.6.33.x |
| oracle / mysql | 5.7.0 | 5.7.15.x |
| wolfssl / wolfssl | - | 3.9.10 |
| debian / debian_linux | 8.0 | 8.0.x |