CVE-2025-11624

Severity CVSS v4.0:
LOW
Type:
CWE-787 Out-of-bounds Write
Publication date:
21/10/2025
Last modified:
04/12/2025

Description

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wolfssh:wolfssh:*:*:*:*:*:*:*:* 1.3.0 (including) 1.4.20 (including)


References to Advisories, Solutions, and Tools