#VU125381 Out-of-bounds read in Botan - CVE-2026-32877
Published: April 8, 2026
Botan
Randombit
Description
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the SM2 decryption authentication code value (C3) check when processing a crafted SM2 ciphertext with an undersized C3 hash field. A remote attacker can send a specially crafted SM2 ciphertext to cause a denial of service and disclose sensitive information.
The over-read is limited to up to 31 bytes and may result in other undefined behavior.