High severity7.3NVD Advisory· Published Dec 29, 2023· Updated Jun 17, 2026
CVE-2023-7158
CVE-2023-7158
Description
A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.22.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249180.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:*range: <1.22.0
- (no CPE)range: <=1.21.0
- (no CPE)
Patches
Vulnerability mechanics
References
9- github.com/micropython/micropython/pull/13039/commits/f397a3ec318f3ad05aa287764ae7cef32202380fnvdPatch
- github.com/micropython/micropython/issues/13007nvdExploitIssue Tracking
- vuldb.comnvdPermissions RequiredThird Party Advisory
- vuldb.comnvdThird Party Advisory
- github.com/micropython/micropython/pull/13039nvdIssue Tracking
- github.com/micropython/micropython/releases/tag/v1.22.0nvdRelease Notes
- lists.fedoraproject.org/archives/list/[email protected]/message/4E2HYWCZB5R4SHY4SZZZSFDMD64N4SOZ/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/D3WWY5JY4RTJE25APB4REGDUDPATG6H7/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/TEK46QAJOXXDZOWOIE2YACUOCZFWOBCK/nvd
News mentions
0No linked articles in our index yet.