In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to… (CVE-2026-15442)
CVE-2026-15442 is a heap-use-after-free vulnerability affecting all builds using (D)TLS, including default builds. It arises during the TLS shutdown process when certain conditional states occur. Specifically, if an application performs a partial wolfSSL_read() due to a small user buffer, then calls wolfSSL_shutdown for a bidirectional close, and attempts another wolfSSL_read() while the peer continues sending data, a heap-use-after-free condition may occur. This vulnerability has a CVSS score of 5.3, indicating a low severity impact primarily affecting availability.
AI Analysis
Technical Summary
This vulnerability exists in all builds that utilize (D)TLS, including default configurations. During the TLS shutdown sequence, a series of conditional states can lead to a heap-use-after-free error. The issue manifests when an application receives a partial read via wolfSSL_read(), often caused by a small user buffer, then initiates a bidirectional shutdown with wolfSSL_shutdown, and subsequently attempts another read while the peer continues to send data. This sequence can cause the internal state machine to access freed heap memory, leading to potential application instability or crashes. The vulnerability is identified as CWE-416 (Use After Free).
Potential Impact
The vulnerability can cause a heap-use-after-free condition, which may lead to application crashes or denial of service due to memory corruption. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, applications should avoid calling wolfSSL_read() after wolfSSL_shutdown during bidirectional shutdown sequences if the peer may still send data. Monitor vendor communications for updates and patches.
In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to… (CVE-2026-15442)
Description
CVE-2026-15442 is a heap-use-after-free vulnerability affecting all builds using (D)TLS, including default builds. It arises during the TLS shutdown process when certain conditional states occur. Specifically, if an application performs a partial wolfSSL_read() due to a small user buffer, then calls wolfSSL_shutdown for a bidirectional close, and attempts another wolfSSL_read() while the peer continues sending data, a heap-use-after-free condition may occur. This vulnerability has a CVSS score of 5.3, indicating a low severity impact primarily affecting availability.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in all builds that utilize (D)TLS, including default configurations. During the TLS shutdown sequence, a series of conditional states can lead to a heap-use-after-free error. The issue manifests when an application receives a partial read via wolfSSL_read(), often caused by a small user buffer, then initiates a bidirectional shutdown with wolfSSL_shutdown, and subsequently attempts another read while the peer continues to send data. This sequence can cause the internal state machine to access freed heap memory, leading to potential application instability or crashes. The vulnerability is identified as CWE-416 (Use After Free).
Potential Impact
The vulnerability can cause a heap-use-after-free condition, which may lead to application crashes or denial of service due to memory corruption. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, applications should avoid calling wolfSSL_read() after wolfSSL_shutdown during bidirectional shutdown sequences if the peer may still send data. Monitor vendor communications for updates and patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rjf7-5h4x-wj8p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-15442"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6ac139bba43b0b3b89d69d51
Added to database: 10/03/2026, 17:22:03 UTC
Last enriched: 10/03/2026, 17:43:28 UTC
Last updated: 10/04/2026, 02:46:03 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.