← לוח פגיעויות

CVE-2026-6681

בינונית 5.3

תיאור (מקור, אנגלית)

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 4.0
1.0 (LOW) מקור הציון: CNA CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-14/8/2026
CWE
CWE-120, CWE-787

מוצרים מושפעים

wolfssl: wolfssl

קישורים