PT-2026-107390 · Wolfssl · Wolfssh
CVE-2026-84897
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y |
Name of the Vulnerable Software and Affected Versions
wolfSSL wolfSSH versions 1.2.0 through 1.5.0
Description
In the
src/internal.c file, the server incorrectly accepts server-to-client Diffie-Hellman group exchange messages, specifically SSH MSG KEX DH GEX GROUP (31) and SSH MSG KEX DH GEX REPLY (33), from unauthenticated clients. This occurs because the IsMessageAllowedServer() function fails to apply a direction check to the key exchange message range when the peer is keying and no specific message is expected. Consequently, the server may execute the client-side handler DoKexDhGexGroup(), which processes attacker-supplied groups. In version 1.5.0, this involves performing two 8-round Miller-Rabin primality tests on values up to 8192 bits. Versions 1.2.0 through 1.4.22 enter the same client-role path without these primality tests. Builds that define WOLFSSH NO DH GEX SHA256, WOLFSSH NO DH, or NO SHA256 are not affected.Recommendations
Update wolfSSL wolfSSH to a version later than 1.5.0.
As a temporary mitigation, define
WOLFSSH NO DH GEX SHA256, WOLFSSH NO DH, or NO SHA256 during the build process to disable the affected functionality.Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssh