PT-2026-29124 · Botan · Botan
Harutokimura
·
Published
2026-03-30
·
Updated
2026-03-31
·
CVE-2026-32877
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Botan versions 2.3.0 through 3.10.9
Description
Botan is a C++ cryptography library. During SM2 decryption, the code that checks the authentication code value (C3) does not verify the encoded value's length before comparison. This can lead to a heap over-read of up to 31 bytes from an invalid ciphertext, potentially causing a crash or undefined behavior.
Recommendations
Update to version 3.11.0 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Botan