CVE-2026-22212

TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility. The vulnerability is caused by unsafe use of strcpy() and strcat() functions when constructing device paths during automatic device discovery. A local attacker can exploit this by creating specially crafted filenames under /dev/usb/, leading to stack memory corruption and application crashes.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 23:15

Updated : 2026-01-13 14:03


NVD link : CVE-2026-22212

Mitre link : CVE-2026-22212

CVE.ORG link : CVE-2026-22212


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow