Impact
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating‑point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR‑based Arduino boards. The fix is included starting from the `1.8.8` release.
Affected Systems
Versions of ArduinoCore‑avr prior to 1.8.8 are affected. All boards that rely on the Arduino AVR Boards platform and compile firmware using these earlier versions are vulnerable. Updating to release 1.8.8 or newer resolves the vulnerability.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the overflow by supplying extreme float or double values during firmware execution on boards using the vulnerable ArduinoCore‑avr. The overflow corrupts the stack and, under specific conditions, could allow attacker‑controlled code execution, but the exploitability requires additional firmware manipulation. Given the lack of widespread attacks and the low EPSS, the overall risk remains moderate.
OpenCVE Enrichment