Buffer Overflow Risk in lwIP SMTP Client from Vendor lwIP
CVE-2026-15340

9.3CRITICAL

Key Information:

Vendor

Savannah

Vendor
CVE Published:
9 October 2026

What is CVE-2026-15340?

The lwIP SMTP client exhibits a vulnerability where it fails to adequately validate input sizes, potentially leading to a buffer overflow situation. This flaw could allow an attacker to exploit the buffer overflow, which may result in unauthorized access or execution of arbitrary code. Organizations using affected versions of lwIP should implement mitigation strategies to protect their systems from possible exploitation of this vulnerability.

Affected Version(s)

lwIP SMTP client 2.2.1

lwIP SMTP client patch_125_smtp_txbuf.diff

lwIP SMTP client git commit (614420f82c8729d070e01464c0dddb3c9525c772)

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xchglabs reported this vulnerability directly to Savannah and then disclosed once the fix was released.
.