A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.
"2026-04-12T09:58:16Z"
[
{
"id": "CVE-2024-48075-26053188",
"target": {
"file": "src/SharkSSL.c",
"function": "registerclass"
},
"deprecated": false,
"digest": {
"function_hash": "116193305503772636673916818953474959206",
"length": 4429.0
},
"signature_type": "Function",
"source": "https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2",
"signature_version": "v1"
},
{
"id": "CVE-2024-48075-83259e85",
"target": {
"file": "src/SharkSSL.c",
"function": "handleptrauth"
},
"deprecated": false,
"digest": {
"function_hash": "52588606717552594754350960731798784924",
"length": 8981.0
},
"signature_type": "Function",
"source": "https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2",
"signature_version": "v1"
},
{
"id": "CVE-2024-48075-cd957411",
"target": {
"file": "src/SharkSSL.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"296383553456154227019804201007982696045",
"139558402534532404322075431506175794548",
"57243565003680671761225258895222600141",
"124328239768517688657460062501883496030",
"263077822661664730474083990502323313256",
"47418585029071527733331880509740951522",
"280915899864689282767928938327850371108",
"81857769488931520861334125977086995630",
"219930885227605519137682339246165832014",
"158956598792563712455775452587847608131",
"83194762082125372655139678522306670887",
"326141084118160352954792430288821377950",
"193590586275851735075943357431325309077",
"337380596445218799214882255252218917703",
"40758777183056723520896790404111525750",
"274270759000240239180116153072587772014",
"280915899864689282767928938327850371108"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/realtimelogic/sharkssl/commit/7045f6f254060640ff77eef2027f108fcc20e2f2",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48075.json"