Skip to content

[v5.8.2] Backport CVE-2025-15346: Fix CERT_REQUIRED verify mode not setting SSL_VERIFY_FAIL_IF_NO_PEER_CERT and th - #68

Open
vulgraph wants to merge 1 commit into
wolfSSL:v5.8.2from
vulgraph:backport/CVE-2025-15346-v5.8.2
Open

vulgraph wants to merge 1 commit into
wolfSSL:v5.8.2from
vulgraph:backport/CVE-2025-15346-v5.8.2

Conversation

@vulgraph

@vulgraph vulgraph commented May 4, 2026

Copy link
Copy Markdown

Backport of upstream fix for CVE-2025-15346 to v5.8.2.

  • Upstream commit: b4517dece7 — Fix CERT_REQUIRED verify mode not setting SSL_VERIFY_FAIL_IF_NO_PEER_CERT and therefore failing to verify the client cer
  • Cherry-picked with git cherry-pick -x (original author preserved).

Apply was clean against the current tip of the target branch. No code changes on top of the upstream fix.

…CERT and therefore failing to verify the client cert.

Thanks to Matan Radomski for the report.

(cherry picked from commit b4517de)
@wolfSSL-Bot

Copy link
Copy Markdown

Can one of the admins verify this patch?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants