CVE Explorer
CVE-2026-55958
Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so execution falls through to an XMEMCPY that writes past the end of the buffer once the accumulated TLS 1.3 handshake transcript exceeds MSGBAG_SIZE (8 KB), corrupting adjacent heap state and potentially causing a remote denial of service crash. The bag is sized to hold a normal handshake, so this is rea
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-787","description":"CWE-787 Out-of-bounds Write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-393","description":"CWE-393 Return of Wrong Status Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/problemTypes/0/descriptions/1
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/wolfSSL/wolfssl","defaultStatus":"unaffected","product":"wolfSSL","vendor":"wolfSSL","versions":[{"lessThanOrEqual":"5.9.1","status":"affected","version":"5.4.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.3,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-787","description":"CWE-787 Out-of-bounds Write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-393","description":"CWE-393 Return of Wrong Status Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/problemTypes/0/descriptions/1
Source references
2 source assertions{"tags":["patch"],"url":"https://github.com/wolfSSL/wolfssl/pull/10705"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/references/0
{"url":"https://www.wolfssl.com/docs/security-vulnerabilities/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a4e4428ab08688273824f93a871ee86e69ad1646cf4d5aac4e60f74a9eb30e41 · sha256:e349b28246bcb894… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.