在 wolfSSL 的 wolfSSH 模块中,src/port.c 文件中的 wstrncat() 函数存在无符号整数下溢漏洞,影响版本范围为 v1.4.11 至 v1.5.0(非 Windows 平台)。经过身份验证的远程攻击者可通过发送精心构造的 SFTP 路径,在栈缓冲区末尾之外写入一个越界的空字节(null byte)。 wolfSSH_RealPath() 函数位于 src/ssh.c,在拼接每个路径组件时,使用的是剩余空间大小(outSz - curSz)而非完整的目标缓冲区大小。因此,当累积路径长度
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfSSH | 1.4.11 ~ 1.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16516 | 9.0 CRITICAL | wolfSSH ECDSA host key curve not validated against negotiated algorithm |
| CVE-2026-84897 | 6.9 MEDIUM | wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated |
| CVE-2026-81535 | 6.3 MEDIUM | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorizat |
No comments yet