Executive brief
ArduinoCore-avr is the core library that provides programming support for Arduino AVR-based microboards. A stack-based buffer overflow vulnerability in the String class allows attackers to cause memory corruption and denial of service by passing large floating-point values to concatenation functions. Under specific conditions, this could enable arbitrary code execution on affected Arduino boards, compromising the integrity and availability of embedded systems relying on this library.
Technical details
The vulnerability is a stack-based buffer overflow in the `String::concat()` methods for float and double types in cores/arduino/WString.cpp. The root cause is that the fixed-size 20-byte stack buffer was insufficient to hold the string representation of floating-point values at the extremes of the float or double range when processed by the `dtostrf()` function. An attacker can trigger the overflow by passing large magnitude float or double values directly to `String::concat(float)`, `String::concat(double)`, `String::operator+=()`, or the `+` operator with float/double operands. No authentication or network access is required—only the ability to run code on the Arduino board. This memory corruption can cause denial of service and, under specific conditions, arbitrary code execution. The fix was released in version 1.8.8 on May 21, 2026, which increases the buffer size to accommodate the maximum representable float and double values.
Affected products
- Arduino ArduinoCore-avr prior to 1.8.8
Timeline
- 2026-09-11: disclosed
- 2026-05-21: patched: Fix included in version 1.8.8