PT-2026-64464 · Julia · Wolfssl Jll
Published
2026-07-14
·
Updated
2026-07-14
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
An integer overflow vulnerability existed in the static function
wolfssl add to chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl add to chain is called by these API: wolfSSL CTX add extra chain cert, wolfSSL CTX add1 chain cert, wolfSSL add0 chain cert. These API are enabled for 3rd party compatibility features: enable-opensslall, enable-opensslextra, enable-lighty, enable-stunnel, enable-nginx, enable-haproxy. This issue is not remotely exploitable, and would require that the application context loading certificates is compromised.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wolfssl Jll