{"id":"CVE-2026-8836","summary":"lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow","details":"A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue.","modified":"2026-06-18T04:13:45.987214255Z","published":"2026-05-18T18:45:12.791Z","database_specific":{"cna_assigner":"VulDB","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8836.json","cwe_ids":["CWE-119","CWE-121"]},"references":[{"type":"WEB","url":"https://savannah.nongnu.org/bugs/?68194"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8836.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8836"},{"type":"ADVISORY","url":"https://vuldb.com/submit/829798"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/364474"},{"type":"REPORT","url":"https://vuldb.com/vuln/364474/cti"},{"type":"FIX","url":"https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=0c957ec03054eb6c8205e9c9d1d05d90ada3898c"},{"type":"FIX","url":"https://github.com/lwip-tcpip/lwip/commit/0c957ec03054eb6c8205e9c9d1d05d90ada3898c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://cgit.git.savannah.gnu.org/cgit/lwip.git","events":[{"introduced":"0"},{"fixed":"0c957ec03054eb6c8205e9c9d1d05d90ada3898c"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/lwip-tcpip/lwip","events":[{"introduced":"0"},{"fixed":"0c957ec03054eb6c8205e9c9d1d05d90ada3898c"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.1.0"},{"last_affected":"2.1.1"},{"last_affected":"2.1.2"},{"last_affected":"2.1.3"},{"last_affected":"2.2.0"},{"last_affected":"2.2.1"}]}}],"versions":["STABLE-2_2_1_RELEASE","STABLE-2_2_0_RELEASE","STABLE-2_2_0_RC1","STABLE-2_1_0_RELEASE","STABLE-2_1_0_RC1","master_at_STABLE-2_0_0","cvs-repository-moved-to-git","STABLE-1_4_0","STABLE-1_4_0-RC2","STABLE-1_4_0-RC1","STABLE-1_3_2","STABLE-1_3_2-RC1","STABLE-1_3_1","STABLE-1_3_1-RC3","STABLE-1_3_1-RC2","STABLE-1_3_1-RC1","STABLE-1_3_0","STABLE-1_3_0-RC1","STABLE-1_1_1","STABLE-1_1_0","STABLE-1_1_0-RC1","STABLE-1_0_0","POST_PACK_REMOVE","PRE_PACK_REMOVE","merged_from_main_to_STABLE-0_7","STABLE-0_7_0","STABLE-0_6_5","STABLE-0_6_4","merged_from_main_to_STABLE","merged_from_main_to_DEVEL","PRE_ARCH_MOVE","POST_REMOVE_ARCH","PRE_leon-dhcp"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-8836.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X"}]}