CVE-2026-30363 Details
Description
flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.
A stack overflow vulnerability has been identified in the Flipper Zero firmware, specifically in the main function of the code. This issue arises from a fixed stack allocation of 1024 bytes, which is insufficient for certain execution scenarios that may require up to 1464 bytes. The vulnerability was introduced in commit ad2a80 and potentially affects earlier versions as well.
The vulnerability has been addressed in a subsequent commit by increasing the stack allocation for the main function to a safer level.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2026CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/k6dpvrmm8z-glitch/7db9fb648a18ffcd8600bea436486884 | CISA-ADP | Technical Description |
| https://github.com/flipperdevices/flipperzero-firmware/issues/4332 | CISA-ADP | Issue TrackingTechnical DescriptionVendor |
| https://gist.github.com/k6dpvrmm8z-glitch/7db9fb648a18ffcd8600bea436486884 | [email protected] | Technical Description |
| https://github.com/flipperdevices/flipperzero-firmware/issues/4332 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| flipperdevices flipperzero-firmware | <ad2a800> |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | [email protected] |
Volerion