Skip to content

Potential reception buffer overflow

Moderate
mluis1 published GHSA-559p-6xgm-fpv9 May 26, 2020

Package

LoRaMac.c soft-se.c lr1110-se.c atecc608a-tnglora-se.c (LoRaMac-node)

Affected versions

< 4.4.4

Patched versions

4.4.4

Description

Impact

Reception buffer overflow can happen due to the received buffer size not being checked.

Patches

Commit e3063a9 fixes this vulnerability and is available on develop and feature/5.0.0 branches.
Will be released with 4.4.4 version

Workarounds

Patch earlier versions with changes provided by commit e3063a9

References

N/A

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-11068

Weaknesses

No CWEs

Credits