CVE-2026-15340 PUBLISHED

Savannah lwIP SMTP client Classic Buffer Overflow

Assigner: icscert
Reserved: 09.07.2026 Published: 09.10.2026 Updated: 09.10.2026

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Savannah
Product lwIP SMTP client
Versions Default: unaffected
  • Version 2.2.1 is affected
  • Version patch_125_smtp_txbuf.diff is unaffected
  • Version git commit (614420f82c8729d070e01464c0dddb3c9525c772) is unaffected

Solutions

xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb3c9525c772)

Credits

  • xchglabs reported this vulnerability directly to Savannah and then disclosed once the fix was released. finder

References

Problem Types

  • CWE-120 CWE