Executive brief
A memory management flaw was identified in the firmware for Striso control hardware, which is used in musical instruments. The software allocates insufficient memory for a specific background process that handles button inputs. If this memory limit is exceeded during operation, it could lead to unpredictable device behavior or system crashes.
Technical details
A stack-based buffer overflow exists in the ThreadReadButtons function within button_read.c of the striso-control-firmware (commit 54c9722). The firmware defines a working area (waThreadReadButtons) of 128 bytes for the thread; however, static analysis of stack usage indicates that the function and its call tree (including update_button and chThdSleep) can require up to 248 bytes. This discrepancy can lead to a thread stack exhaustion/overflow during normal execution. An attacker or specific runtime conditions could trigger a crash or undefined behavior by exhausting the allocated stack space.
Affected products
- Striso striso-control-firmware 54c9722
Timeline
- 2024-12-05: disclosed: Issue reported on GitHub repository
- 2026-05-13: advisory: CVE published by NVD