PT-2026-102413 · Mcumgr · Mcumgr

·

CVE-2026-18747

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions MCUmgr (affected versions not specified)
Description An integer underflow exists in the SMP-over-console transport when processing base64 frames. The function mcumgr serial process frag() in subsys/mgmt/mcumgr/transport/src/serial util.c unconditionally subtracts 2 from the buffer length to strip the CRC. Because mcumgr serial extract len() allows a declared length of 0 or 1, the net buf::len variable (a uint16 t) underflows, causing the system to treat a small buffer as having approximately 65 KB of payload.
This can be triggered by an unauthenticated 7-byte line sent to the management console via transports using CONFIG MCUMGR TRANSPORT UART or CONFIG MCUMGR TRANSPORT SHELL. The underflow allows smp process request packet() in subsys/mgmt/mcumgr/smp/src/smp.c to bypass boundary checks. By staging specific buffer contents, an attacker can cause net buf pull() to move the parse cursor out of bounds, leading to an out-of-bounds read. This may result in a denial of service by faulting the MCUmgr thread or lead to memory disclosure via the CONFIG MCUMGR GRP OS ECHO handler.
Recommendations Update the software to a version where mcumgr serial extract len() rejects declared packet lengths of two bytes or fewer. As a temporary mitigation, restrict write access to the management console, such as the USB CDC-ACM port or UART header.

Exploit

Fix

DoS

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18747
GHSA-G6CX-XJ75-HVFW

Affected Products

Mcumgr