Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.
A size computation for the SquashFS directory table overflows on an attacker-controlled superblock field, producing an undersized allocation and subsequent out-of-bounds writes when U-Boot parses a crafted SquashFS image during boot.
The lwIP MQTT client does not enforce the MQTT limit on fixed-header length, so a malicious or man-in-the-middle broker can send a run of remaining-length continuation bytes and drive an unbounded write past a 128-byte heap buffer in the client. No MQTT authentication is required, and the primitive is a plausible path to remote code execution.
Unchecked src_len in the RSA NOPAD paths underflows the copy destination, writing attacker-controlled bytes below the core heap buffer.
Unchecked src_len in the SE050 driver's RSA NOPAD paths underflows the copy destination, writing attacker-controlled bytes below the core heap buffer.
// No embargoed advisories.