Intel

AIKIDO-2025-10991

wolfSSL.wolfssh is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2025-11624 Published Dec 29, 2025

40

Medium Risk

This Affects:

C++wolfSSL.wolfssh
0.0.1 - 1.4.20
Fixed in 1.4.21
Are you affected? Scan for Free

TL;DR

A potential stack-based buffer overflow exists when processing a file handle supplied by an SFTP client. After an SFTP connection is established, a malicious client can send crafted read, write, or set-state SFTP packets that cause the server-side SFTP code to write to stack memory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wolfSSL.wolfssh is vulnerable to Out-of-bounds Write in versions 0.0.1 - 1.4.20.

How to fix this

Upgrade the wolfSSL.wolfssh library to the patch version.