Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-15340: Debian lwIP SMTP client can overflow memory
CVE-2026-15340 · published today
Summary
The SMTP client component of the lwIP library used in Debian does not verify how much data it receives, which could let an attacker cause the program to write beyond its allocated space. This may lead to a crash or allow malicious code to run. Update to the latest Debian package that includes the fix or apply the vendor’s security patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | savannah | lwip smtp client | 2.2.1 |
| Debian:12 | debian | lwip | All versions |
Original advisory text
DEBIAN-CVE-2026-15340
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Severity
9.9
Critical
Type
CWE-120Classic Buffer Overflow
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta