Description
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating‑point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR‑based Arduino boards. The fix is included starting from the `1.8.8` release.

Affected Systems

Versions of ArduinoCore‑avr prior to 1.8.8 are affected. All boards that rely on the Arduino AVR Boards platform and compile firmware using these earlier versions are vulnerable. Updating to release 1.8.8 or newer resolves the vulnerability.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. The EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the overflow by supplying extreme float or double values during firmware execution on boards using the vulnerable ArduinoCore‑avr. The overflow corrupts the stack and, under specific conditions, could allow attacker‑controlled code execution, but the exploitability requires additional firmware manipulation. Given the lack of widespread attacks and the low EPSS, the overall risk remains moderate.

Generated by OpenCVE AI on September 15, 2026 at 20:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArduinoCore‑avr to version 1.8.8 or later.
  • Refactor firmware to avoid concatenating large floating‑point values onto Arduino String objects or use safer conversion functions.
  • Convert float or double values to a string representation only after ensuring they are within a safe numeric range to prevent overflow.

Generated by OpenCVE AI on September 15, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arduino
Arduino arduinocore-avr
Vendors & Products Arduino
Arduino arduinocore-avr

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point values of sufficiently large magnitude onto an Arduino String object. By passing values near the extremes of the float or double range to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with a float/double operand, `dtostrf()` writes beyond the fixed-size stack buffer, causing memory corruption and denial of service. Under specific conditions, this could enable arbitrary code execution on AVR-based Arduino boards. The fix is included starting from the `1.8.8 `release.
Title ArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatenation handler
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Arduino Arduinocore-avr
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:17:38.993Z

Reserved: 2026-05-21T15:33:08.291Z

Link: CVE-2026-48490

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:23.978Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:10.100

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-48490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')