8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Description
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release.
AI Analysis
Heap buffer overflow in DTLS 1.3 ACK serialization due to integer truncation
Basic Information
ID
CVE-2026-6679
Source
wolfSSL
Published
Jun 25, 2026 at 20:13
Affected Product
Vendor
wolfSSL
Product
wolfSSL
Version
5.4.0
Affected Versions
wolfSSL wolfSSL 5.4.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
wolfSSL
Product
wolfSSL
Version
5.9.0 and earlier