PT-2026-6683 · Unknown · Micropython

Oneafter

·

Published

2026-02-06

·

Updated

2026-02-11

·

CVE-2026-1998

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions micropython versions prior to 1.27.0
Description A flaw exists in micropython up to version 1.27.0. This issue is related to memory corruption caused by manipulation of the mp import all function within the py/runtime.c file. The attack requires local access. An exploit for this issue has been published.
Recommendations Install the patch 570744d06c5ba9dba59b4c3f432ca4f0abd396b6 to address this issue.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-1998
OPENSUSE-SU-2026:10156-1
OPENSUSE-SU-2026:20199-1

Affected Products

Micropython