CVE-2024-8948 is a critical heap-based buffer overflow vulnerability affecting MicroPython version 1.23.0, specifically within the mpz_as_bytes function when converting zero from an integer to bytes. This flaw can be exploited remotely with low attack complexity, potentially leading to a denial of service (DoS) due to the high impact on availability. While a patch (908ab1ceca15ee6fd0ef82ca4cba770a3ec41894) is available and recommended, there is currently no evidence of active exploitation, nor are there publicly available exploits in common frameworks or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.23.0CPE matchmatch criteria | cpe:2.3:a:micropython:micropython:1.23.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.