Answer in brief
CVE-2026-62381 records a Medium severity (CVSS 6.9) vulnerability in luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow. The current sources do not mark it as known exploited. The current feed maps openwrt/luci (generic), openwrt/luci (generic), openwrt/luci-lib-px5g (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps openwrt/luci (generic), openwrt/luci (generic), openwrt/luci-lib-px5g (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| openwrt/lucigeneric | 0 | Not reported |
| openwrt/lucigeneric | >=0 <=42d72f79cd8f057f241595abc761b39dab2d9f07 | Not reported |
| openwrt/luci-lib-px5ggeneric | >=0 <=42d72f79cd8f057f241595abc761b39dab2d9f07 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256 bytes, requiring one additional DER length octet. As a result the allocation is 259 bytes while the tag, length, unused-bits byte, and signature require 260 bytes, and the final memcpy writes one byte beyond the heap buffer. The overflow is reachable through the exported Lua interface via create_selfsigned(); whether it is remotely exploitable depends on the embedding application. The vulnerable code is present on the openwrt-18.06 through openwrt-25.12 release branches and is absent from master, where the luci-lib-px5g package has been removed rather than patched.
Quoted source text, attributed separately from HOL analysis.