PT-2026-29124 · Botan · Botan

Harutokimura

·

Publicado

2026-03-30

·

Atualizado

2026-03-31

·

CVE-2026-32877

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Botan versions 2.3.0 through 3.10.9
Description Botan is a C++ cryptography library. During SM2 decryption, the code that checks the authentication code value (C3) does not verify the encoded value's length before comparison. This can lead to a heap over-read of up to 31 bytes from an invalid ciphertext, potentially causing a crash or undefined behavior.
Recommendations Update to version 3.11.0 or later.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07567
CVE-2026-32877
GHSA-7JJ6-4R42-W9H6

Produtos afetados

Botan