Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
The lwIP MQTT client does not enforce the MQTT limit on fixed-header length, so a malicious or man-in-the-middle broker can send a run of remaining-length continuation bytes and drive an unbounded write past a 128-byte heap buffer in the client. No MQTT authentication is required, and the primitive is a plausible path to remote code execution.
Unchecked src_len in the RSA NOPAD paths underflows the copy destination, writing attacker-controlled bytes below the core heap buffer.
TA_FLAG_CONCURRENT is accepted from user TA headers, letting two sessions race on one shared context and free vm_region nodes that are still in use.
Unchecked src_len in the SE050 driver's RSA NOPAD paths underflows the copy destination, writing attacker-controlled bytes below the core heap buffer.
// No embargoed advisories.