Skip to content
Brief Security & Trust ·

CISA flags buffer overflow in Savannah lwIP SMTP client; patch is out

The US agency says the flaw could crash devices or let attackers run code remotely, and a fix has been released.

In brief
  • CISA says a buffer overflow in the Savannah lwIP SMTP client could crash a device or allow remote code execution.
  • xchglabs says a patch is out. CISA advisory ICSA-26-279-02 has the full details.

CISA, the US cyber agency, published an advisory on 6 October 2026 about a flaw in the Savannah lwIP SMTP client. SMTP is the standard way software sends email. CISA said a successful attack could crash the device. The overflow may also let an attacker run their own code from a distance. CISA lists energy and water and wastewater systems as the affected sectors. It says xchglabs reported the flaw to Savannah privately and went public once a fix was out. According to xchglabs, the fix is a patch file named patch_125_smtp_txbuf.diff, also available as a git commit.

CISA labels the weakness CWE-120, a classic buffer overflow. A program copies data into a space without first checking that the data fits. The extra data spills past the end of that space. That is how a crash or remote code execution can follow. For the list of affected versions and any severity details, readers should consult CISA advisory ICSA-26-279-02.

Email-sending code can be a small part of a device's software, and it may not show up in an asset list. Operators can ask whether their device firmware includes this client and who is responsible for patching it. CISA also tells operators to keep control systems off the internet and behind firewalls, apart from business networks. It adds that VPNs, used for remote access, can have flaws of their own.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: CISA.