{"id":"CVE-2020-11068","details":"In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4.","aliases":["GHSA-559p-6xgm-fpv9"],"modified":"2026-08-18T13:13:38.203282Z","published":"2020-06-23T17:15:11.500Z","references":[{"type":"FIX","url":"https://github.com/Lora-net/LoRaMac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4"},{"type":"FIX","url":"https://github.com/Lora-net/LoRaMac-node/security/advisories/GHSA-559p-6xgm-fpv9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lora-net/loramac-node","events":[{"introduced":"0"},{"fixed":"ba17382bd5109513937afad07f068a781a503ef6"},{"fixed":"e3063a91daa7ad8a687223efa63079f0c24568e4"}],"database_specific":{"cpe":"cpe:2.3:a:semtech:loramac-node:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.4.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v4.4.3","v4.4.2","v4.4.2-rc.7","v4.4.2-rc.6","v4.4.2-rc.5","4.4.2-rc.4","v4.4.2-rc.3","v4.4.2-rc.2","v4.4.2-rc.1","v4.0.0","v4.3.0","v4.2.0","v4.1.0","v3.4.1","V3.4","v3.3","v3.2","v3.1","v3.0","v2.3.RC2","v2.3.RC1","v2.2","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11068.json","vanir_signatures_modified":"2026-08-18T13:13:38Z","vanir_signatures":[{"digest":{"line_hashes":["217943513229331974053177570341904374095","158229748252261799029226800678054978975","257417098436523763359627050287874618484","25502565422967047204298405231183211323","65784995682968914060774190354734000253","227905730767439064633267358346307995013","10271869559989751747744332288236947360","92088805706696705966372640674638221742"],"threshold":0.9},"id":"CVE-2020-11068-06e3ddf5","signature_type":"Line","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4","target":{"file":"src/mac/LoRaMac.c"},"deprecated":false},{"target":{"file":"src/peripherals/atecc608a-tnglora-se/atecc608a-tnglora-se.c"},"deprecated":false,"digest":{"line_hashes":["187279422351008881163045226212769455854","334431603000567321990112645809611874811","149712001136221002528868900505496561655"],"threshold":0.9},"id":"CVE-2020-11068-11dd77fd","signature_type":"Line","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4"},{"deprecated":false,"digest":{"function_hash":"77552535904026823327571985916187162076","length":9734},"id":"CVE-2020-11068-681c59fd","signature_type":"Function","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4","target":{"function":"ProcessRadioRxDone","file":"src/mac/LoRaMac.c"}},{"target":{"file":"src/peripherals/lr1110-se/lr1110-se.c"},"deprecated":false,"digest":{"line_hashes":["187279422351008881163045226212769455854","334431603000567321990112645809611874811","149712001136221002528868900505496561655"],"threshold":0.9},"id":"CVE-2020-11068-6aa9e653","signature_type":"Line","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4"},{"digest":{"function_hash":"104639005086380311500882123505189001892","length":1954},"id":"CVE-2020-11068-988d2ca2","signature_type":"Function","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4","target":{"file":"src/peripherals/soft-se/soft-se.c","function":"SecureElementProcessJoinAccept"},"deprecated":false},{"target":{"file":"src/peripherals/lr1110-se/lr1110-se.c","function":"SecureElementProcessJoinAccept"},"deprecated":false,"digest":{"function_hash":"2985876363264467897231117159574642002","length":1324},"id":"CVE-2020-11068-9b512c72","signature_type":"Function","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4"},{"deprecated":false,"digest":{"line_hashes":["187279422351008881163045226212769455854","334431603000567321990112645809611874811","149712001136221002528868900505496561655"],"threshold":0.9},"id":"CVE-2020-11068-b1007c0a","signature_type":"Line","signature_version":"v1","source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4","target":{"file":"src/peripherals/soft-se/soft-se.c"}},{"source":"https://github.com/lora-net/loramac-node/commit/e3063a91daa7ad8a687223efa63079f0c24568e4","target":{"file":"src/peripherals/atecc608a-tnglora-se/atecc608a-tnglora-se.c","function":"SecureElementProcessJoinAccept"},"deprecated":false,"digest":{"function_hash":"104639005086380311500882123505189001892","length":1954},"id":"CVE-2020-11068-df0f7ad0","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}