TROYANOSYVIRUS
Volver a CVEs

CVE-2026-22211

N/A

Descripcion

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s format specifiers using strcat() without verifying remaining buffer capacity. When printfUART is invoked with a caller-controlled string longer than the available space, the unbounded sprintf/strcat sequence writes past the end of debugbuf, resulting in global memory corruption. This can cause denial of service, unintended behavior, or information disclosure via corrupted adjacent global state or UART output.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado1/14/2026
Ultima modificacion1/14/2026
Fuentenvd
Avistamientos honeypot0

Debilidades (CWE)

CWE-787

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.