Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15442— Heap use-after-free on read during bidirectional (D)TLS shutdown

Quick assessment

Affected
wolfSSL wolfSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在所有使用 (D)TLS 的构建版本中,包括默认构建版本,都存在一系列在 TLS 关闭过程中的条件状态,可能导致堆上的使用后释放(heap-use-after-free)漏洞。如果应用程序执行 wolfSSL_read() 时因传入的小用户缓冲区而收到部分读取结果,随后调用 wolfSSL_shutdown() 执行双向关闭,并在对等方仍在尝试发送数据的情况下再次调用 wolfSSL_read(),则会导致进入一种可能触发堆使用后释放漏洞的状态。

CVSS 2.3 · Low EPSS 0.28% · P19

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15442

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap use-after-free on read during bidirectional (D)TLS shutdown
Source: CVE Program / CVE List V5
Vulnerability Description
In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is sometimes caused by a small user buffer passed in, then called wolfSSL_shutdown for a bidirectional close and attempted to wolfSSL_read() again while the peer continues trying to send data during the shutdown it would lead to a state where a potential heap-use-after free happened.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL wolfSSL 4.4.0 ~ 5.9.2 -

II. Public POCs for CVE-2026-15442

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15442

请登录查看更多情报信息。

Other References for CVE-2026-15442 (1)

Same Patch Batch · wolfSSL · 2026-09-27 · 11 CVEs total

CVE-2026-93302 8.3 HIGH Trusted peer certificate match ignores public key, allowing forged CA clones
CVE-2026-89136 8.3 HIGH Client accepts unsolicited RawPublicKey server certificate type
CVE-2026-89102 8.3 HIGH OCSP stapling v2 multi accepts non-CA chain certificates as issuers
CVE-2026-93304 6.3 MEDIUM (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
CVE-2026-89133 6.3 MEDIUM NameConstraints not enforced across unconstrained intermediate CA
CVE-2026-89134 6.3 MEDIUM Subject CN name-constraint check bypassed when non-DNS SAN present
CVE-2026-89135 6.3 MEDIUM Failed X509_verify_cert leaves unverified CA in shared CertManager
CVE-2026-94418 2.3 LOW Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
CVE-2026-94419 2.3 LOW Client session cache reference poisoning allows resumption with wrong server
CVE-2026-94417 2.3 LOW CRL check skipped when OCSP enabled and certificate has no OCSP URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-15442

No comments yet


Leave a comment