PT-2026-102413 · Mcumgr · Mcumgr
CVSS v3.1
6.8
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MCUmgr (affected versions not specified)
Description
An integer underflow exists in the SMP-over-console transport when processing base64 frames. The function
mcumgr serial process frag() in subsys/mgmt/mcumgr/transport/src/serial util.c unconditionally subtracts 2 from the buffer length to strip the CRC. Because mcumgr serial extract len() allows a declared length of 0 or 1, the net buf::len variable (a uint16 t) underflows, causing the system to treat a small buffer as having approximately 65 KB of payload.This can be triggered by an unauthenticated 7-byte line sent to the management console via transports using
CONFIG MCUMGR TRANSPORT UART or CONFIG MCUMGR TRANSPORT SHELL. The underflow allows smp process request packet() in subsys/mgmt/mcumgr/smp/src/smp.c to bypass boundary checks. By staging specific buffer contents, an attacker can cause net buf pull() to move the parse cursor out of bounds, leading to an out-of-bounds read. This may result in a denial of service by faulting the MCUmgr thread or lead to memory disclosure via the CONFIG MCUMGR GRP OS ECHO handler.Recommendations
Update the software to a version where
mcumgr serial extract len() rejects declared packet lengths of two bytes or fewer.
As a temporary mitigation, restrict write access to the management console, such as the USB CDC-ACM port or UART header.Exploit
Fix
DoS
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcumgr