Security

Savannah lwIP SMTP client

View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer…

Read at CISA Cybersecurity Advisories

CVE-2026-15340

Severity
9.3 Critical · CVSS 4.0 · Icscert
Exploited
Not in CISA’s catalog
Published
Savannah lwIP SMTP client

Affected: 2.2.1

Fixed: patch_125_smtp_txbuf.diff; git commit (614420f82c8729d070e01464c0dddb3c9525c772)

cisa.gov · github.com · CVE record · NVD