Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.
| Software | From | Fixed in |
|---|---|---|
| wolfssl / wolfssl | 5.8.2 | 5.8.4 |