Stack-based Buffer Overflow in lwIP Product by lwIP Vendor
CVE-2026-8836
9.3CRITICAL
What is CVE-2026-8836?
A vulnerability exists in lwIP due to a stack-based buffer overflow in the snmp_parse_inbound_frame function of the SNMPv3 USM Handler. This flaw arises from manipulating the msgAuthenticationParameters argument, which may potentially allow an attacker to exploit the vulnerability remotely. A patch is available to mitigate this issue, and it is strongly recommended that users apply it to enhance their security.
Affected Version(s)
lwIP 2.1.0
lwIP 2.1.1
lwIP 2.1.2
