AI analysis
CVE-2026-15442 is a heap use-after-free (CWE-416) in wolfSSL during TLS or DTLS shutdown, present in every build that uses (D)TLS, including default builds. It is reached when an application gets a partial wolfSSL_read—often because the caller passed a small buffer—then calls wolfSSL_shutdown for a bidirectional close and calls wolfSSL_read again while the peer is still sending data during shutdown, leaving heap memory used after it is freed. CVSS 4.0 scores this 2.3 (low): network-reachable with low privileges, but high complexity and extra attack requirements, and impact limited to low availability (a potential crash), with no confidentiality or integrity impact. Products and devices that embed wolfSSL for TLS or DTLS are in scope. It is not on the CISA Known Exploited Vulnerabilities list, and no public proof-of-concept is known; related coverage states that wolfSSL 5.9.4 fixes a set of TLS flaws.
What to do: Upgrade to wolfSSL 5.9.4 or any later build that includes the TLS shutdown fix, and rebuild every product that links wolfSSL with (D)TLS enabled. Prioritize applications that pass a small buffer to wolfSSL_read, then call wolfSSL_shutdown for a bidirectional close and read again. There is no public proof-of-concept and the issue is not on the CISA KEV list; until patched, treat unexpected crashes during TLS close as a possible hit on this bug.
Affected
| wolfSSL | All builds that use TLS or DTLS, including default builds; related release coverage identifies wolfSSL 5.9.4 as the fix (the CVE text does not list a numeric af |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is sometimes caused by a small user buffer passed in, then called wolfSSL_shutdown for a bidirectional close and attempted to wolfSSL_read() again while the peer continues trying to send data during the shutdown it would lead to a state where a potential heap-use-after free happened.