目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-83742— wolfSSH wstrncat()整数下溢导致空字节越界写入漏洞

一分钟漏洞结论

影响对象
wolfSSL Inc. wolfSSH
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 wolfSSL 的 wolfSSH 模块中,src/port.c 文件中的 wstrncat() 函数存在无符号整数下溢漏洞,影响版本范围为 v1.4.11 至 v1.5.0(非 Windows 平台)。经过身份验证的远程攻击者可通过发送精心构造的 SFTP 路径,在栈缓冲区末尾之外写入一个越界的空字节(null byte)。 wolfSSH_RealPath() 函数位于 src/ssh.c,在拼接每个路径组件时,使用的是剩余空间大小(outSz - curSz)而非完整的目标缓冲区大小。因此,当累积路径长度

CVSS 5.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-83742 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms
来源: CVE Program / CVE List V5
Vulnerability Description
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N
来源: CVE Program / CVE List V5
Vulnerability Type
整数下溢(超界折返)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
wolfSSL Inc. wolfSSH 1.4.11 ~ 1.5.0 -

二、漏洞 CVE-2026-83742 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-83742 的情报信息

请登录查看更多情报信息。

CVE-2026-83742 补丁与修复 (4)

同批安全公告 · wolfSSL Inc. · 2026-10-07 · 共 4 条

CVE-2026-16516 9.0 CRITICAL wolfSSH ECDSA主机密钥曲线未验证
CVE-2026-84897 6.9 MEDIUM wolfSSH 服务器接受未认证客户端的DH组交换消息,导致CPU耗尽和密钥交换角色混淆
CVE-2026-81535 6.3 MEDIUM wolfSSH SSH客户端未授权接受未请求的转发-tcpip通道

IV. Related Vulnerabilities

V. Comments for CVE-2026-83742

暂无评论


发表评论