Double-free Vulnerability in BoringSSL Public Key Initialization in Swift Crypto
CVE-2026-43823
Currently unrated
What is CVE-2026-43823?
A severe double-free vulnerability occurs during the initialization of an RSA public key from DER or PEM bytes in Swift Crypto. This issue arises when BoringSSL encounters a failure to decode the public key from the provided byte data, leading to the EVP_PKEY structure being incorrectly freed twice. Such improper memory management can result in application crashes during subsequent memory allocations. The vulnerability has been rectified in Swift Crypto version 4.5.1, which addresses the issue to enhance the security and stability of the software.
Affected Version(s)
swift-crypto 0 < 4.5.1