Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 26 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wolfssl
Wolfssl wolfssl |
|
| Vendors & Products |
Wolfssl
Wolfssl wolfssl |
Thu, 25 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and then overrun. This affects builds using DTLS 1.3 and wolfSSL version 5.9.0 and earlier. A fix was added to the 5.9.1 release. | |
| Title | DTLS 1.3 ACK serialization heap buffer overflow via integer truncation | |
| Weaknesses | CWE-190 CWE-197 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: wolfSSL
Published:
Updated: 2026-06-26T13:13:41.022Z
Reserved: 2026-04-20T15:00:29.102Z
Link: CVE-2026-6679
Updated: 2026-06-26T13:13:37.879Z
Status : Analyzed
Published: 2026-06-25T21:16:28.167
Modified: 2026-06-27T20:26:02.470
Link: CVE-2026-6679
No data.
OpenCVE Enrichment
Updated: 2026-06-26T01:15:04Z