PT-2026-6683 · Unknown · Micropython
Oneafter
·
Published
2026-02-06
·
Updated
2026-02-11
·
CVE-2026-1998
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
micropython versions prior to 1.27.0
Description
A flaw exists in micropython up to version 1.27.0. This issue is related to memory corruption caused by manipulation of the
mp import all function within the py/runtime.c file. The attack requires local access. An exploit for this issue has been published.Recommendations
Install the patch 570744d06c5ba9dba59b4c3f432ca4f0abd396b6 to address this issue.
Exploit
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Micropython