AI analysis
An unsigned integer underflow in the wstrncat() helper (src/port.c) of wolfSSL wolfSSH versions 1.4.11 through 1.5.0 on non-Windows platforms lets an authenticated remote attacker write a single out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. The SFTP real-path handler wolfSSH_RealPath() (src/ssh.c) bounds each appended path component by the remaining space (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX and the strncat() call becomes effectively unbounded; a component that exactly fills the remaining space then writes its terminating null one byte past the end of the stack buffer. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that one null byte, which can corrupt an adjacent stack value and crash the process (denial of service). However, applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to a potentially unbounded copy, because the word32 expression outSz - segSz in that length check also wraps. The flaw is fixed in wolfSSH 1.6.0; there is no known public proof of concept, it is not in the CISA KEV catalog, and no exploitation in the wild has been reported.
What to do: Upgrade to wolfSSH 1.6.0 or later — the first release after the affected range, which fixes five wolfSSH flaws including a critical MITM host-key verification bypass — and check with embedded-device vendors for firmware updates bundling it. As an interim measure, restrict SFTP access to trusted authenticated accounts and networks or disable SFTP if unused, since exploitation requires valid SSH credentials. Audit any first-party code calling the public wolfSSH_RealPath() to ensure output buffers are at least as large as the input path, which rules out the more severe unbounded-copy variant.
Affected
| wolfSSL wolfSSH | 1.4.11 through 1.5.0 on non-Windows platforms (SFTP/wolfSSH_RealPath code paths; fixed in 1.6.0) |
Description
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.