yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-6681
Component Overview
Vulnerability Overview
Name
CVE-2026-6681
Source
NVD (
link
)
Debian (
link
)
Description
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.
CWEs
CWE-120
Published Date
Jun 25, 2026
Updated Date
Jun 27, 2026
Workaround
-
Advisories
https://github.com/wolfSSL/wolfssl/pull/10116
Issue Tracking
https://www.wolfssl.com/docs/security-vulnerabilities/
Vendor Advisory
Analysis
#
Affected Component
Analysis
wolfssl
Exploitable
Vulnerability Ratings
#
1
CVSSv4
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
wolfssl
buildroot
2025.02.x
5.9.2
Not Affected
wolfssl
buildroot
master
5.9.2
Not Affected
wolfssl
openwrt
master
5.9.2-r1
Not Affected
wolfssl
openwrt
openwrt-25.12
5.9.2-r1
Not Affected
wolfssl
yocto
kirkstone
5.2.0
Exploitable
wolfssl
yocto
master
5.9.2
Not Affected