CyberRota Analysis
AI-GeneratedA vulnerability exists in the handling of revoked-key error paths, where a heap buffer overflow occurs due to insufficient allocation size for the formatted error message generated by sprintf(). This flaw can lead to potential arbitrary code execution or denial of service, making it critical for organizations using affected products to prioritize remediation. Security teams should assess their systems for this vulnerability to mitigate risks associated with exploitation.
Original NVD Description
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.