CVE 8.8 HIGH

DTLS 1.3 ACK serialization heap buffer overflow via integer truncation_CVE-2026-6679

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Description

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release.

AI Analysis

Heap buffer overflow in DTLS 1.3 ACK serialization due to integer truncation

Basic Information

ID CVE-2026-6679
Source wolfSSL
Published Jun 25, 2026 at 20:13

Affected Product

Vendor wolfSSL
Product wolfSSL
Version 5.4.0
Affected Versions wolfSSL wolfSSL 5.4.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor wolfSSL
Product wolfSSL
Version 5.9.0 and earlier

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.