Vulnerability record · CVE-2022-39173 · published 29 September 2022
CVE-2022-39173: Wolfssl out-of-bounds write vulnerability
Wolfssl · Wolfssl
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
Description
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/169600/wolfSSL-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2022/Oct/24 | Mailing ListThird Party Advisory |
| https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/ | |
| https://github.com/wolfSSL/wolfssl/releases | Release NotesThird Party Advisory |
| https://www.wolfssl.com/docs/security-vulnerabilities/ | Vendor Advisory |
| http://packetstormsecurity.com/files/169600/wolfSSL-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2022/Oct/24 | Mailing ListThird Party Advisory |
| https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/ | |
| https://github.com/wolfSSL/wolfssl/releases | Release NotesThird Party Advisory |
| https://www.wolfssl.com/docs/security-vulnerabilities/ | Vendor Advisory |
Track CVE-2022-39173 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-39173), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.