PT-2026-26312 · Wolfssl · Wolfssl
Maor Caplan
·
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2026-0819
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
A stack buffer overflow issue exists in the PKCS7 SignedData encoding functionality of wolfSSL. Specifically, the
wc PKCS7 BuildSignedAttributes() function incorrectly calculates the capacity value passed to the EncodeAttributes() function when adding custom signed attributes. This leads to writing beyond the bounds of the signedAttribs[7] array, resulting in stack memory corruption. In builds utilizing a small stack, this can manifest as heap corruption. Successful exploitation requires an application that permits untrusted input to control the size of the signedAttribs array when calling wc PKCS7 EncodeSignedData() or related signing functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssl