Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb3c9525c772)
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow. | |
| Title | Savannah lwIP SMTP client Classic Buffer Overflow | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-09T14:52:43.517Z
Reserved: 2026-07-09T19:50:39.306Z
Link: CVE-2026-15340
No data.
Status : Awaiting Analysis
Published: 2026-10-09T15:17:13.510
Modified: 2026-10-09T17:29:33.410
Link: CVE-2026-15340
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:45:09Z
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')