Logo
vulnerabilityCVE-2026-6681
Name
CVE-2026-6681
Source
NVD ( link)Debian ( link)
Description
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
wolfssl
Exploitable

Vulnerability Ratings#


1
CVSSv4
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.9.2
Not Affected
buildroot
master
5.9.2
Not Affected
openwrt
master
5.9.2-r1
Not Affected
openwrt
openwrt-25.12
5.9.2-r1
Not Affected
yocto
kirkstone
5.2.0
Exploitable
yocto
master
5.9.2
Not Affected