CVE-2026-6325: Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
Published Jun 25, 2026
·Updated
Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.
Affected Software
1 affected component
wolfSSL wolfssl>=4.8.0<5.9.2
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6325?
The severity of CVE-2026-6325 is classified as low with a CVSS score of 4.0.
2
What causes the CVE-2026-6325 vulnerability?
CVE-2026-6325 is caused by an out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list.
3
How do I fix CVE-2026-6325?
To fix CVE-2026-6325, apply the available patch from wolfSSL.
4
What software is affected by CVE-2026-6325?
CVE-2026-6325 affects the wolfSSL library.
5
When was CVE-2026-6325 published?
CVE-2026-6325 was published on June 25, 2026.