MEDIUM
Heap buffer overflow in CertFromX509() via AuthorityKeyIdentifier
Published Apr 9, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.22%
Description
Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate internally due to incorrect size handling of the AuthorityKeyIdentifier extension.
Affected products
-
Affected
- ≥ 0, < 5.9.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability doesn't affect any versions of MariaDB as shipped with Red Hat Products. For Red Hat products MariaDB is compiled and linked against the system's OpenSSL library instead of using the MariaDB's bundled WolfSSL library routines.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-5447 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2457074 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21183 Advisory
- https://github.com/wolfSSL/wolfssl/pull/10112 Issue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2026-5447
- https://www.cve.org/CVERecord?id=CVE-2026-5447
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5447 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2457074 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21183 | Advisory | |
| https://github.com/wolfSSL/wolfssl/pull/10112 | Issue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-5447 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-5447 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Apr 9, 2026
Updated Apr 10, 2026
Reserved Apr 2, 2026
Link CVE-2026-5447
CISA Vulnrichment
Updated Apr 10, 2026
GitHub
No data