Heap Buffer Overflow in openFPGALoader Utility for FPGAs by Trabucayre
CVE-2026-35176
7.1HIGH
What is CVE-2026-35176?
The openFPGALoader utility for programming FPGAs contains a vulnerability due to a heap-buffer-overflow in the POFParser::parseSection() function. This flaw allows for out-of-bounds access to heap memory when a specially crafted .pof file is parsed. Importantly, the vulnerability can be triggered without requiring any FPGA hardware, posing a serious risk for users working with this tool. Users are advised to update to the latest version to mitigate potential exploitation.
Affected Version(s)
openFPGALoader <= 1.1.1
