CVE-2022-42961
NixOS vulnerability analysis and mitigation

Overview

A fault injection vulnerability (CVE-2022-42961) was discovered in wolfSSL before version 5.5.0. The vulnerability involves a Rowhammer attack on RAM that can lead to ECDSA key disclosure. This vulnerability affects users performing signing operations with private ECC keys, such as those used in server-side TLS connections (NVD, wolfSSL Release).

Technical details

The vulnerability is classified as a fault injection attack that specifically targets RAM through Rowhammer technique. When users perform operations with private ECC keys, such as server-side TLS connections and creating ECC signatures, the attack can lead to the disclosure of ECDSA keys. The vulnerability is considered Low severity and affects systems that could be targeted with a sophisticated Rowhammer attack (wolfSSL Release).

Impact

The primary impact of this vulnerability is the potential disclosure of ECDSA private keys. This could compromise the security of TLS connections and digital signatures, particularly affecting server-side operations where private ECC keys are used for authentication and secure communication (NVD).

Mitigation and workarounds

The vulnerability has been addressed in wolfSSL version 5.5.0. Users should update to this version or later and compile using the macro WOLFSSLCHECKSIG_FAULTS. This is particularly important for users who have hardware that could be targeted with a Rowhammer attack (wolfSSL Release).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • rhel10::thunderbird-flatpak
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management