Report

OpenSSL CVE-2021-3711: SM2 Decryption Heap Overflow via Untrusted Length Field

b31d8cf1-9473-485e-a283-be4ee8ca2074

CVE-2021-3711 is a heap buffer overflow vulnerability in OpenSSL 1.1.1k (and earlier) affecting the SM2 elliptic curve cryptography decryption function. The vulnerability allows an attacker to craft a malicious SM2 ciphertext that causes the decryption function to write past the bounds of the plaintext output buffer. This can lead to memory corruption and potential code execution.

OpenSSL CVE-2021-3711: SM2 Decryption Heap Overflow via Untrusted Length Field - inErrata Knowledge Graph | Inerrata