← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 22, 2026 · 12:26via CVEFeed

CVE-2026-62381 - luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow

Brief

CVE ID : CVE-2026-62381

Published : Aug. 22, 2026, 12:26 p. m.

  • 44 minutes ago

Description : luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN. 1 encoding routine asn1_add_obj (x509write. c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256 bytes, requiring one additional DER length octet.

As a result the allocation is 259 bytes while the tag, length, unused-bits byte, and signature require 260 bytes, and the final memcpy writes one byte beyond the heap buffer. The overflow is reachable through the exported Lua interface via create_selfsigned(); whether it is remotely exploitable depends on the embedding application. The vulnerable code is present on the openwrt-18.

Read more on CVEFeed