PT-2026-26322 · Wolfssl · Wolfssl
Haruto Kimura
·
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2026-2646
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
A heap-buffer-overflow issue exists in the
wolfSSL d2i SSL SESSION() function. When deserializing session data with SESSION CERTS enabled, the lengths of certificate and session ID are read from untrusted input without validation, potentially leading to a heap memory overflow. A crafted session loaded from an external source is required to trigger this issue. Internal sessions are not affected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssl