CVE-2026-22212: TinyOS <= 2.1.2 Stack-Based Buffer Overflow in mcp2200gpio

Published Jan 12, 2026
·
Updated

TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility. The vulnerability is caused by unsafe use of strcpy() and strcat() functions when constructing device paths during automatic device discovery. A local attacker can exploit this by creating specially crafted filenames under /dev/usb/, leading to stack memory corruption and application crashes.

Affected Software

1 affected component
TinyOS TinyOS<=2.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TinyOS (mcp2200gpio) to a version that resolves this vulnerability.

    Fixed in 2.1.2
  2. Compensating control

    Prevent local attackers from creating specially crafted filenames under /dev/usb/ (e.g., restrict access/permissions to the /dev/usb/ path used for automatic device discovery).

Event History

Jan 12, 2026
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Apr 12, 58019
Event
via FIRST·04:07 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-22212?

CVE-2026-22212 has a high severity rating due to the stack-based buffer overflow that can lead to code execution.

2

How do I fix CVE-2026-22212?

To fix CVE-2026-22212, upgrade to a version of TinyOS that is higher than 2.1.2 where the vulnerability is patched.

3

What systems are affected by CVE-2026-22212?

CVE-2026-22212 affects TinyOS versions up to and including 2.1.2, particularly in the mcp2200gpio utility.

4

What type of vulnerability is CVE-2026-22212?

CVE-2026-22212 is a stack-based buffer overflow vulnerability caused by unsafe string manipulation functions.

5

Who is impacted by CVE-2026-22212?

Users and developers using TinyOS versions 2.1.2 and earlier are impacted by CVE-2026-22212.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203