Apple

Swift-crypto

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 23.07.2026 14:33:20
  • Zuletzt bearbeitet 23.07.2026 19:16:54

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL c...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 03.04.2026 01:32:28
  • Zuletzt bearbeitet 24.07.2026 21:10:00

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto ve...