PT-2024-18128 · Wolfssl+1 · Wolfssl+1

Junkai Liang

+3

·

Published

2024-04-04

·

Updated

2026-01-27

·

CVE-2024-1545

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WolfSSL version 5.6.6
Description A Fault Injection vulnerability in the RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c allows a remote attacker co-residing in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure. This issue affects the wolfcrypt library.
Recommendations For version 5.6.6, consider disabling the RsaPrivateDecryption function as a temporary workaround until a patch is available. Restrict access to the wolfcrypt library to minimize the risk of exploitation. Avoid using the RsaKey structure in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unchecked Return Value

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-1545

Affected Products

Debian
Wolfssl