PULSE
FEED
ransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomthegentlemen reclama a Groupe APROSEP · SN · Otherransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomthegentlemen reclama a Groupe APROSEP · SN · Other
← Todos los CVEs
CVE Watch29 sept 2026

CVE-2026-18747

The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally

CVSS

6.8

Medio

EPSS

0.1%

p1

KEV

—

Exploit Today

0

0-100

Publicado: 29 sept 2026 · Última mod.: 29 sept 2026 · CWE-125 · CWE-191

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console — the 0x06 0x09 packet marker followed by the base64 group AAA= and a newline — delivered to any transport built on this helper: CONFIG_MCUMGR_TRANSPORT_UART (smp_uart.c) or CONFIG_MCUMGR_TRANSPORT_SHELL (smp_shell.c), both of which select MCUMGR_TRANSPORT_SERIAL_HAS_SMP_OVER_CONSOLE. No prior session state, fragmentation or credentials are required to trigger the underflow, and the malformed frame is mishandled before any command handler or command-level access control runs. The attacker only needs write access to that console, which on many boards is a USB CDC-ACM port rather than a bare UART header. With the inflated length, smp_process_request_packet() in subsys/mgmt/mcumgr/smp/src/smp.c loses its bound: cbor_nb_reader_init() gives the CBOR decoder a ~65 KB window into a 384-byte buffer, and each request header's nh_len is checked only against the inflated length. On its own the 7-byte frame re-parses whatever stale bytes the reused pool buffer still holds, typically a replay of the previously received request followed by a parse error, without leaving the buffer. Because the transport is unauthenticated, though, the attacker also controls the frames sent before the trigger, and can stage buffer contents so that a request succeeds with an nh_len larger than the buffer; net_buf_pull(), guarded only by __ASSERT_NO_MSG, then moves the parse cursor out of bounds and the loop reads further headers and CBOR from adjacent memory. The consequence is an out-of-bounds read that can fault the MCUmgr thread (denial of service); memory disclosure is also possible, since the default-enabled os echo handler (CONFIG_MCUMGR_GRP_OS_ECHO) decodes its string inside that window and copies it into its response. There is no integrity gain beyond what the unauthenticated transport already permits. The fix rejects any declared packet length of two bytes or fewer in mcumgr_serial_extract_len(), so the CRC-strip subtraction can no longer underflow. The identical pattern remains in the test-only loopback transport subsys/mgmt/mcumgr/transport/src/smp_dummy.c (CONFIG_MCUMGR_TRANSPORT_DUMMY), which has no external input path and therefore carries no practical exposure.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-86133—
—
——0An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.11h
CVE-2026-86132—
—
——0An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.11h
CVE-2026-1023184.7 MED
—
——0Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)13h
CVE-2026-1028206.2 MED
—
——0pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.16h
CVE-2026-102757—
—
——0An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged service could dereference an object address a module named by asking only whether that address fell outside the module. The manager's object pool is outside every module, so the test was satisfied by an address shifted into the interior of one of the module's own privileged allocations, which denotes no object at all. The bytes such an address presents as a control block are bytes the module put there through ordinary create and set services, so the control block ID at the front of them could be made to read as any type the module chose, and the `_txe_` layer's ID test then agreed. The reported chain uses that to reach a privileged `memset` across an attacker-chosen range.17h
CVE-2026-102726—
—
——0Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read16h