CVE-2020-17529

CRITICAL

Apache NuttX <9.1.0, 10.0.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/12/09/5

Scores

CVSS v3 9.8
EPSS 0.0143
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (2)
apache/nuttx 10.0.0
apache/nuttx < 9.1.0
Published Dec 09, 2020
Tracked Since Feb 18, 2026