Public Security Advisories
Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.
On a storage failure U-Boot's lwIP wget receive callback aborts and frees the TCP connection but returns the wrong status code, so the lwIP TCP input path keeps using the freed connection object, a use-after-free reachable from a malicious HTTP server.
The lwIP MQTT client does not enforce the MQTT limit on fixed-header length, so a malicious or man-in-the-middle broker can send a run of remaining-length continuation bytes and drive an unbounded write past a 128-byte heap buffer in the client. No MQTT authentication is required, and the primitive is a plausible path to remote code execution.
// No embargoed advisories.