Heap Buffer Overflow in wolfSSL DTLS 1.3 Serialization Path
CVE-2026-6679
8.8HIGH
What is CVE-2026-6679?
A vulnerability has been identified in the wolfSSL library that allows for a heap buffer overflow during the DTLS 1.3 ACK serialization process before peer authentication occurs. This issue arises from improper size calculations leading to integer truncation, which then causes an undersized buffer allocation that can be overrun. Users of wolfSSL versions 5.9.0 and earlier are advised to upgrade to version 5.9.1, where a fix has been implemented to mitigate this risk.
Affected Version(s)
wolfSSL 5.4.0 <= 5.9.0
