CVE-2026-83742

Source
https://cve.org/CVERecord?id=CVE-2026-83742
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83742.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-83742
Published
2026-10-07T02:41:48Z
Modified
2026-10-09T07:06:13Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:N CVSS Calculator
Summary
wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms
Details

Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.

Database specific
{
    "cna_assigner": "wolfSSL",
    "cwe_ids": [
        "CWE-121",
        "CWE-191",
        "CWE-193"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83742.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.4.11"
                },
                {
                    "fixed": "1.6.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/wolfssl/wolfssh

Affected ranges

Type
GIT
Repo
https://github.com/wolfssl/wolfssh
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "v1.4.11"
        },
        {
            "fixed": "v1.5.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.4.11-stable
v1.4.12-stable
v1.4.13-stable
v1.4.14-stable
v1.4.15-stable
v1.4.16
v1.4.17-stable
v1.4.18-stable
v1.4.19-stable
v1.4.20-stable
v1.4.21-stable
v1.4.22-stable

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83742.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "328782627089980915604203644033779900281",
                "107115627691394170917680407599490627877",
                "267209229727525357394632461804842782902",
                "76651518498038347550901080500469668092",
                "105479741633168716250627150652240791825",
                "9070111367816151677222613645760329457",
                "50672913637094273091227496104925419314",
                "167826218478033831759525794374507740602"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-170af4e3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "tests/unit.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "27734006313293991581910682330469645194",
                "244225124737887375103049749516966221524",
                "320372759377710900840240351445895152019",
                "309145385289991851458710101946212264320"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-1fe1ae2b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/certman.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "244585327027838163698571260816539718374",
            "length": 6309
        },
        "id": "CVE-2026-83742-271d9f06",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "src/wolfscp.c",
            "function": "wsScpRecvCallback"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "252335614001664091872469254032211762287",
            "length": 824
        },
        "id": "CVE-2026-83742-327a9045",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/agent.c",
            "function": "DoAgentLock"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "93386517751082817204828624318964388451",
                "329231145859969397111865132226295826597",
                "26886328020351798829087892885131963644",
                "14526179109789376122530664560426192402"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-4a93821a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "wolfssh/internal.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "295083623554350041393542767027713327285",
            "length": 366
        },
        "id": "CVE-2026-83742-4c2380f9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/port.c",
            "function": "wstrncat"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "211945164755852043592698308722964998407",
                "81882821428357002564130137324657056108",
                "113606698930018470923873604406007794927",
                "189369053373420869689253845983004496019",
                "231153091679321517617700913124170793201",
                "140988282004911932849096464534004216946",
                "71300888906486836064900103854582215287",
                "49686712317641110784947213599024346285",
                "293130776508293253743869203478562964800",
                "291771394920782844097220836349549088072",
                "36580699217804279581117762094889114385"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-521e28df",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/agent.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "251680018158351330088037080069993075337",
                "208464830422980481707516247508333631637",
                "301868057695286279193226304961700835756",
                "232080957704815633841605260905193360850"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-536f1755",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/822e4464560b467580ea37a2fc03b0988d88b71f",
        "target": {
            "file": "src/port.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "19693075822069235529462084032203303261",
                "54691454620205766953100837110583268592",
                "206890439412972764096454640057731157201",
                "146889756358983614092854137000460146676",
                "287878195605063589182705336126981119400",
                "249330971852762421118886193854794110763",
                "281666759812233831876389428104248683012",
                "204941700836354459221724533863323729533",
                "143386616257770635088331626602863597648",
                "213136697543504042942336410426157414233",
                "231031005613904578718376821450921740492"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-7f0a051d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "src/ssh.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "327856727688399447317320195753174595561",
            "length": 312
        },
        "id": "CVE-2026-83742-830fc6e0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/certman.c",
            "function": "wolfSSH_CERTMAN_LoadRootCA_buffer"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "155131168440534427932971479509419149697",
            "length": 1303
        },
        "id": "CVE-2026-83742-b249e7e1",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "src/ssh.c",
            "function": "wolfSSH_RealPath"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "129782321920653900341622070511068805612",
            "length": 9580
        },
        "id": "CVE-2026-83742-ce6a9e1f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "tests/unit.c",
            "function": "wolfSSH_UnitTest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "53619029943271743926278699540653574933",
                "197271327857248347451582511685844755223",
                "282502313899123526831129386702283385758",
                "228304462265690583984055185829012358518",
                "73459527975338414171570077569536230243",
                "308385671224263640749049169613033669582",
                "320817682581050204357809152609584343191"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-cea67cbb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35",
        "target": {
            "file": "src/wolfscp.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "64459432919527274325776960330705914575",
            "length": 751
        },
        "id": "CVE-2026-83742-daa12ace",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/agent.c",
            "function": "DoAgentUnlock"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "296851137307614251056930148461949340938",
            "length": 304
        },
        "id": "CVE-2026-83742-e20b71c4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/822e4464560b467580ea37a2fc03b0988d88b71f",
        "target": {
            "file": "src/port.c",
            "function": "wstrncat"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "56132233173538126565354710276979973735",
                "69691055874485430765952762581225393731",
                "271509245092073909574110749770313961113",
                "272908638898091896726429205051465023858",
                "107980904001839078980455061073458443708"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-83742-e949ec8b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/wolfssl/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de",
        "target": {
            "file": "src/port.c"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:13Z"