Junglewise Threat Intelligence

CVE-2025-28343: Striso striso-control-firmware stack overflow in ThreadReadButtons

CVE-2025-28343 · Severity: info · CVSS 0 · Published 2026-05-13

Executive brief

A memory management flaw was identified in the firmware for Striso control hardware, which is used in musical instruments. The software allocates insufficient memory for a specific background process that handles button inputs. If this memory limit is exceeded during operation, it could lead to unpredictable device behavior or system crashes.

Technical details

A stack-based buffer overflow exists in the ThreadReadButtons function within button_read.c of the striso-control-firmware (commit 54c9722). The firmware defines a working area (waThreadReadButtons) of 128 bytes for the thread; however, static analysis of stack usage indicates that the function and its call tree (including update_button and chThdSleep) can require up to 248 bytes. This discrepancy can lead to a thread stack exhaustion/overflow during normal execution. An attacker or specific runtime conditions could trigger a crash or undefined behavior by exhausting the allocated stack space.

Affected products

  • Striso striso-control-firmware 54c9722

Timeline

  • 2024-12-05: disclosed: Issue reported on GitHub repository
  • 2026-05-13: advisory: CVE published by NVD

References

Related threats