Stack-based Buffer Overflow in lwIP Product by lwIP Vendor
CVE-2026-8836

9.3CRITICAL

Key Information:

Vendor

lwIP

Status
Vendor
CVE Published:
18 May 2026

What is CVE-2026-8836?

A vulnerability exists in lwIP due to a stack-based buffer overflow in the snmp_parse_inbound_frame function of the SNMPv3 USM Handler. This flaw arises from manipulating the msgAuthenticationParameters argument, which may potentially allow an attacker to exploit the vulnerability remotely. A patch is available to mitigate this issue, and it is strongly recommended that users apply it to enhance their security.

Affected Version(s)

lwIP 2.1.0

lwIP 2.1.1

lwIP 2.1.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0rbitingZer0 (VulDB User)
.