PT-2026-26365 · Wolfssl · Wolfssl
Kunyuk
+1
·
Publicado
2026-03-19
·
Atualizado
2026-04-30
·
CVE-2026-3229
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
wolfssl (affected versions not specified)
Description
An integer overflow issue was identified in the
wolfssl add to chain function, leading to heap corruption when certificate data exceeded the bounds of the certificate buffer. The function is utilized by the following API endpoints: wolfSSL CTX add extra chain cert, wolfSSL CTX add1 chain cert, and wolfSSL add0 chain cert. This issue is not remotely exploitable and requires a compromise of the application context loading certificates. The issue is triggered when using 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, and enable-haproxy.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wolfssl