Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-83742— wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms

Quick assessment

Affected
wolfSSL Inc. wolfSSH
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 wolfSSL 的 wolfSSH 模块中,src/port.c 文件中的 wstrncat() 函数存在无符号整数下溢漏洞,影响版本范围为 v1.4.11 至 v1.5.0(非 Windows 平台)。经过身份验证的远程攻击者可通过发送精心构造的 SFTP 路径,在栈缓冲区末尾之外写入一个越界的空字节(null byte)。 wolfSSH_RealPath() 函数位于 src/ssh.c,在拼接每个路径组件时,使用的是剩余空间大小(outSz - curSz)而非完整的目标缓冲区大小。因此,当累积路径长度

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-83742

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms
Source: CVE Program / CVE List V5
Vulnerability Description
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N
Source: CVE Program / CVE List V5
Vulnerability Type
整数下溢(超界折返)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wolfSSL Inc. wolfSSH 1.4.11 ~ 1.5.0 -

II. Public POCs for CVE-2026-83742

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-83742

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-83742 (4)

Same Patch Batch · wolfSSL Inc. · 2026-10-07 · 4 CVEs total

CVE-2026-16516 9.0 CRITICAL wolfSSH ECDSA host key curve not validated against negotiated algorithm
CVE-2026-84897 6.9 MEDIUM wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated
CVE-2026-81535 6.3 MEDIUM wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorizat

IV. Related Vulnerabilities

V. Comments for CVE-2026-83742

No comments yet


Leave a comment