CVE 1.8 LOW

Buffer overwrite when processing file handles with the SFTP server_CVE-2025-11624

1.8 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:L

Description

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.

Basic Information

ID CVE-2025-11624
Source wolfSSL
Published Oct 21, 2025 at 13:14
Modified Oct 21, 2025 at 14:08

Affected Product

Vendor wolfSSH
Product wolfSSH
Version 1.3.0
Affected Versions wolfSSH wolfSSH 1.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.