CVE-2020-17528

CRITICAL

Apache NuttX <10.0.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/12/09/4

Scores

CVSS v3 9.1
EPSS 0.0174
EPSS Percentile 82.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-787
Status published
Products (2)
apache/nuttx 10.0.0
apache/nuttx < 9.1.0
Published Dec 09, 2020
Tracked Since Feb 18, 2026