CVE-2026-5778 - Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.
CVE ID :CVE-2026-5778
Published : April 9, 2026, 10:16 p.m. | 2 hours, 52 minutes ago
Description :Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 9, 2026, 10:16 p.m. | 2 hours, 52 minutes ago
Description :Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...