Executive brief
wolfSSL is a security library used to encrypt data for embedded devices and cloud applications. A flaw in how it handles extremely large messages (over 64 GiB) could allow an attacker to recover the original contents of encrypted data. This occurs because the system fails to stop the encryption process before it starts reusing security keys, which compromises the privacy of the information.
Technical details
A vulnerability exists in wolfSSL's wolfCrypt engine within the AES-GCM streaming API implementation. The functions `wc_AesGcmEncryptUpdate` and `wc_AesGcmDecryptUpdate` do not properly validate or reject cumulative message sizes exceeding 64 GiB. This lack of bounds checking allows the internal 32-bit counter to wrap, leading to keystream reuse (nonce reuse). An attacker capable of observing or influencing these large data streams could exploit this reuse to perform plaintext recovery. The issue was addressed by adding total length overflow checks in `wolfcrypt/src/aes.c`.
Affected products
- wolfSSL wolfSSL 4.8.0 to 5.9.1
Timeline
- 2026-06-16: patched: Fix submitted via GitHub Pull Request 10709
- 2026-06-25: advisory: NVD publication date