Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-15340: Debian lwIP SMTP client can overflow memory

CVE-2026-15340 · published today
Summary

The SMTP client component of the lwIP library used in Debian does not verify how much data it receives, which could let an attacker cause the program to write beyond its allocated space. This may lead to a crash or allow malicious code to run. Update to the latest Debian package that includes the fix or apply the vendor’s security patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– savannah lwip smtp client 2.2.1
Debian:12 debian lwip All versions
Original advisory text
DEBIAN-CVE-2026-15340
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.9 Critical
Type
CWE-120Classic Buffer Overflow
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-15340 · MITRE
Track software like this
Free during beta