CVE-2016-7440: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
Affected products
- Debian Debian Linux: version 8.0 only
- MariaDB MariaDB: from 5.5.0, before 5.5.53 (fixed in 5.5.53); from 10.0.0, before 10.0.28 (fixed in 10.0.28); from 10.1.0, before 10.1.19 (fixed in 10.1.19)
- Oracle MySQL: from 5.5.0, up to and including 5.5.52; from 5.6.0, up to and including 5.6.33; from 5.7.0, up to and including 5.7.15
- wolfSSL wolfSSL: before 3.9.10 (fixed in 3.9.10)
Published 2016-12-13. Last modified 2026-06-17.