Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6681

Опубликовано: 25 июн. 2026
Источник: debian
EPSS Низкий

Описание

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wolfsslfixed5.9.2-1package
wolfsslno-dsatrixiepackage
wolfsslpostponedbullseyepackage

Примечания

  • https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)

EPSS

Процентиль: 17%
0.00257
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

CVSS3: 5.3
nvd
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

CVSS3: 5.3
github
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

EPSS

Процентиль: 17%
0.00257
Низкий