Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release. | |
| Title | ArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatenation handler | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T21:00:06.071Z
Reserved: 2026-05-21T15:33:08.291Z
Link: CVE-2026-48490
No data.
Status : Received
Published: 2026-09-11T21:17:10.100
Modified: 2026-09-11T21:17:10.100
Link: CVE-2026-48490
No data.
OpenCVE Enrichment
Updated: 2026-09-12T05:45:09Z
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')