CVE-2026-15442 Overview
CVE-2026-15442 is a heap use-after-free vulnerability [CWE-416] in wolfSSL affecting all builds that use TLS or DTLS, including default configurations. The flaw occurs during the TLS shutdown sequence when an application performs a bidirectional close after a partial wolfSSL_read(). If the application calls wolfSSL_shutdown() and then invokes wolfSSL_read() again while the peer continues sending data, the library can enter a conditional state that frees memory still referenced by the read path. An attacker who controls the peer side of a TLS connection may trigger the condition and cause memory corruption or denial of service.
Critical Impact
A network-adjacent peer can trigger heap memory corruption during TLS shutdown, potentially leading to denial of service in wolfSSL-based applications.
Affected Products
- wolfSSL builds compiled with TLS support
- wolfSSL builds compiled with DTLS support
- Default wolfSSL build configurations
Discovery Timeline
- 2026-09-27 - CVE-2026-15442 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-15442
Vulnerability Analysis
The vulnerability resides in wolfSSL's TLS shutdown handling logic. The library tracks several conditional states as it transitions a connection through the bidirectional close sequence defined by the TLS specification. A specific ordering of API calls causes the internal state machine to release heap memory that remains reachable through a subsequent read operation.
The trigger sequence requires three conditions. First, the application performs a wolfSSL_read() that returns a partial result, typically because the caller supplied a small user buffer. Second, the application calls wolfSSL_shutdown() to initiate a bidirectional close. Third, the application invokes wolfSSL_read() again while the remote peer continues transmitting application data during the shutdown handshake.
Root Cause
The root cause is improper lifetime management of session buffers during the shutdown transition. The shutdown path frees internal structures associated with pending read data. The read path, when re-entered during an active shutdown with inbound peer traffic, dereferences those freed structures. This matches the pattern described by CWE-416: Use After Free.
Attack Vector
Exploitation requires an active TLS or DTLS session between the vulnerable application and an attacker-controlled peer. The attacker must be able to continue sending record data after the local side begins the shutdown sequence. Attack complexity is high because the window for triggering the race is narrow and depends on the victim application's buffer sizing and read loop structure. The attack does not provide confidentiality or integrity impact against the TLS session itself but can corrupt heap memory in the host process.
See the wolfSSL pull request 10863 for the upstream fix and detailed description of the state transitions involved.
Detection Methods for CVE-2026-15442
Indicators of Compromise
- Unexpected crashes or segmentation faults in processes linked against wolfSSL during or shortly after TLS session termination.
- AddressSanitizer or heap debugger reports flagging use-after-free in wolfSSL read or shutdown code paths.
- Abnormal termination of TLS-enabled services correlated with peer-initiated close sequences.
Detection Strategies
- Audit application source for the call pattern wolfSSL_read() → wolfSSL_shutdown() → wolfSSL_read() with small user buffers.
- Run wolfSSL-linked binaries under AddressSanitizer in CI pipelines to surface the use-after-free during fuzzing of shutdown sequences.
- Inventory deployed wolfSSL versions across the environment and flag any build predating the fix in pull request 10863.
Monitoring Recommendations
- Monitor service crash logs and core dumps for TLS-handling processes, correlating stack traces to wolfSSL shutdown functions.
- Track TLS session termination patterns and alert on repeated abnormal closes from the same peer.
- Collect host-level process restart events for services exposing (D)TLS endpoints.
How to Mitigate CVE-2026-15442
Immediate Actions Required
- Identify all applications and appliances in the environment that embed wolfSSL for TLS or DTLS.
- Upgrade to the wolfSSL release that incorporates the fix from pull request 10863.
- Restart affected services after upgrading the wolfSSL library to ensure the patched code is loaded.
Patch Information
The fix is tracked in wolfSSL pull request 10863, which corrects the state transitions during bidirectional TLS shutdown. Vendors shipping products that statically link wolfSSL must rebuild and redistribute firmware or binaries. Operators relying on dynamically linked wolfSSL should update the shared library and restart dependent processes.
Workarounds
- Avoid calling wolfSSL_read() after wolfSSL_shutdown() has been invoked for a bidirectional close.
- Increase user-supplied read buffer sizes to reduce the likelihood of partial reads that set up the vulnerable state.
- Where protocol semantics allow, perform a unidirectional close instead of waiting for the peer's close_notify.
# Example: verify installed wolfSSL version on a Linux host
wolfssl-config --version
ldconfig -p | grep wolfssl
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.