Skip to main content

CVE-2026-48490: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in arduino ArduinoCore-avr

0
Medium
VulnerabilityCVE-2026-48490cvecve-2026-48490cwe-120
Published: 09/11/2026 (09/11/2026, 21:00:06 UTC)
Source: CVE Database V5
Vendor/Project: arduino
Product: ArduinoCore-avr

Description

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release.

CVSS v4.0

Score 6.9medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected software

arduino

ArduinoCore-avr

Affected versions
<1.8.8
GitHub Actionsmore threats →ai
arduino/ArduinoCore-avr
pkg:github/arduino/ArduinoCore-avr
Affected versions
<1.8.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 21:32:37 UTC

Technical Analysis

CVE-2026-48490 is a classic buffer overflow (CWE-120) in ArduinoCore-avr affecting versions before 1.8.8. The issue arises when concatenating floating-point values near the extremes of the float or double range onto Arduino String objects using String::concat(float), String::concat(double), String::operator+=(), or the + operator with float/double operands. The dtostrf() function writes beyond a fixed-size stack buffer, causing stack-based memory corruption. This can result in denial of service and potentially arbitrary code execution on AVR-based Arduino boards. The vulnerability is addressed in ArduinoCore-avr version 1.8.8 and later.

Potential Impact

An attacker can cause a stack-based buffer overflow by passing large floating-point values to string concatenation functions, leading to memory corruption. This can cause denial of service due to program crashes. Under certain conditions, it may allow arbitrary code execution on affected AVR-based Arduino boards, posing a significant security risk.

Mitigation Recommendations

Upgrade ArduinoCore-avr to version 1.8.8 or later, where the vulnerability is fixed. No other mitigations are specified or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-21T15:33:08.291Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa4701a91cc7f3848aa73e9

Added to database: 09/11/2026, 21:18:18 UTC

Last enriched: 09/11/2026, 21:32:37 UTC

Last updated: 09/11/2026, 22:23:23 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses