CVE-2026-48490: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in arduino ArduinoCore-avr
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release.
AI Analysis
Technical Summary
CVE-2026-48490 is a classic buffer overflow (CWE-120) in ArduinoCore-avr affecting versions before 1.8.8. The issue arises when concatenating floating-point values near the extremes of the float or double range onto Arduino String objects using String::concat(float), String::concat(double), String::operator+=(), or the + operator with float/double operands. The dtostrf() function writes beyond a fixed-size stack buffer, causing stack-based memory corruption. This can result in denial of service and potentially arbitrary code execution on AVR-based Arduino boards. The vulnerability is addressed in ArduinoCore-avr version 1.8.8 and later.
Potential Impact
An attacker can cause a stack-based buffer overflow by passing large floating-point values to string concatenation functions, leading to memory corruption. This can cause denial of service due to program crashes. Under certain conditions, it may allow arbitrary code execution on affected AVR-based Arduino boards, posing a significant security risk.
Mitigation Recommendations
Upgrade ArduinoCore-avr to version 1.8.8 or later, where the vulnerability is fixed. No other mitigations are specified or required.
CVE-2026-48490: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in arduino ArduinoCore-avr
Description
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release.
CVSS v4.0
Score 6.9medium
Affected software
arduino
ArduinoCore-avr
pkg:github/arduino/ArduinoCore-avrRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-48490 is a classic buffer overflow (CWE-120) in ArduinoCore-avr affecting versions before 1.8.8. The issue arises when concatenating floating-point values near the extremes of the float or double range onto Arduino String objects using String::concat(float), String::concat(double), String::operator+=(), or the + operator with float/double operands. The dtostrf() function writes beyond a fixed-size stack buffer, causing stack-based memory corruption. This can result in denial of service and potentially arbitrary code execution on AVR-based Arduino boards. The vulnerability is addressed in ArduinoCore-avr version 1.8.8 and later.
Potential Impact
An attacker can cause a stack-based buffer overflow by passing large floating-point values to string concatenation functions, leading to memory corruption. This can cause denial of service due to program crashes. Under certain conditions, it may allow arbitrary code execution on affected AVR-based Arduino boards, posing a significant security risk.
Mitigation Recommendations
Upgrade ArduinoCore-avr to version 1.8.8 or later, where the vulnerability is fixed. No other mitigations are specified or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-21T15:33:08.291Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa4701a91cc7f3848aa73e9
Added to database: 09/11/2026, 21:18:18 UTC
Last enriched: 09/11/2026, 21:32:37 UTC
Last updated: 09/11/2026, 22:23:23 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.