Executive brief
wolfSSL is a security library used to encrypt data for embedded devices and cloud applications. A flaw in how the library handles certain encrypted messages (PKCS#7) allows data to be written into memory areas where it does not belong. While rated as low severity, this could potentially lead to memory corruption or application instability when processing specially formatted security data.
Technical details
An out-of-bounds write vulnerability exists in wolfSSL's PKCS#7 decoding implementation (CWE-787, CWE-120). The root cause is that the decoding path fails to validate the decoded content length against the caller-supplied 'outputSz' buffer size parameter. An attacker providing a crafted PKCS#7 message could cause the library to write decoded data past the end of the allocated buffer. This affects wolfSSL versions 5.9.0 and earlier; the issue was addressed in version 5.9.1.
Affected products
- wolfSSL wolfSSL 3.10.0 to 5.9.0
Timeline
- 2026-06-25: disclosed: CVE published to NVD
- 2026-04-07: patched: Fix merged into master branch via PR 10116