PT-2026-64472 · Julia · Wolfssl Jll

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc PKCS7 DecryptOri() function in wolfcrypt/src/pkcs7.c. When processing a CMS EnvelopedData message containing an OtherRecipientInfo (ORI) recipient, the function copies an ASN.1-parsed OID into a fixed 32-byte stack buffer (oriOID[MAX OID SZ]) via XMEMCPY without first validating that the parsed OID length does not exceed MAX OID SZ. A crafted CMS EnvelopedData message with an ORI recipient containing an OID longer than 32 bytes triggers a stack buffer overflow. Exploitation requires the library to be built with --enable-pkcs7 (disabled by default) and the application to have registered an ORI decrypt callback via wc PKCS7 SetOriDecryptCb().

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-719

Affected Products

Wolfssl Jll