Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43823

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.

A flaw was found in swift-crypto. When an RSA (Rivest-Shamir-Adleman) public key is initialized from DER (Distinguished Encoding Rules) or PEM (Privacy-Enhanced Mail) formatted bytes, and an error occurs during the decoding process, a double-free vulnerability can be triggered. This issue, occurring when BoringSSL fails to decode the public key, can lead to a system crash due to corrupted memory, resulting in a Denial of Service (DoS).

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-763
https://bugzilla.redhat.com/show_bug.cgi?id=2506494swift-crypto: swift-crypto: Denial of Service due to double-free during RSA public key initialization

EPSS

Процентиль: 17%
0.00256
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
17 дней назад

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.

EPSS

Процентиль: 17%
0.00256
Низкий

6.2 Medium

CVSS3