{"id":"CVE-2020-12887","details":"Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses the CoAP option number field of all options present in the input packet. Each option number is calculated as a sum of the previous option number and a delta of the current option. The delta and the previous option number are expressed as unsigned 16-bit integers. Due to lack of overflow detection, it is possible to craft a packet that wraps the option number around and results in the same option number being processed again in a single packet. Certain options allocate memory by calling a memory allocation function. In the cases of COAP_OPTION_URI_QUERY, COAP_OPTION_URI_PATH, COAP_OPTION_LOCATION_QUERY, and COAP_OPTION_ETAG, there is no check on whether memory has already been allocated, which in conjunction with the option number integer overflow may lead to multiple assignments of allocated memory to a single pointer. This has been demonstrated to lead to memory leak by buffer orphaning. As a result, the memory is never freed.","modified":"2026-08-27T08:40:04.801925Z","published":"2020-06-18T19:15:11.783Z","references":[{"type":"ADVISORY","url":"https://github.com/ARMmbed/mbed-coap/pull/116"},{"type":"ADVISORY","url":"https://github.com/ARMmbed/mbed-os/issues/12930"},{"type":"ADVISORY","url":"https://github.com/ARMmbed/mbed-os/issues/12957"},{"type":"FIX","url":"https://github.com/mjurczak/mbed-coap/commit/4647a68e364401e81dbd370728127d844f221d93"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/PelionIoT/mbed-coap","events":[{"introduced":"4ee0eb3b18267b5be0d42f00dc4cc0660679686b"},{"last_affected":"4ee0eb3b18267b5be0d42f00dc4cc0660679686b"}],"database_specific":{"cpe":"cpe:2.3:a:arm:mbed-coap:5.1.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.1.5"},{"last_affected":"5.1.5"}],"source":"CPE_STRING"}}],"versions":["5.1.5","v5.1.5","mcc-4.6.0","mcc-4.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12887.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/mjurczak/mbed-coap","events":[{"introduced":"0"},{"fixed":"4647a68e364401e81dbd370728127d844f221d93"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v5.1.5","v5.1.4","v5.1.3","pdmc-4.4.0","pdmc-4.3.0","v5.1.2","mcc-4.2.1","mcc-4.2.0","mcc-4.1.0","v5.1.1","mcc-4.0.0","v5.1.0","v5.0.0","v4.8.0","mcc-3.4.0","mcc-3.3.0","v4.7.4","mcc-3.2.0","mcc-3.1.1","mcc-3.1.0","mcc-3.0.0","2.2.1-delta-RC1","2.2.1-RC1","2.2.1","2.2.0-RC8","2.2.0-RC7","2.2.0-RC6","2.2.0","v4.7.3","2.2.0-RC5","2.2.0-RC4","2.2.0-RC2","2.2.0-RC1","v4.7.2","2.1.1-RC4","2.1.1-RC3","2.1.1-RC2","2.1.1","v4.7.1","2.1.1-RC1","2.1.0-RC5","2.1.0-RC4","2.1.0-RC3","2.1.0-RC2","2.1.0-RC1","2.1.0","v4.7.0","v4.6.3","2.0.1.1-RC1","2.0.1-RC2","2.0.1-RC1","2.0.1","2.0.0-RC5","2.0.0-RC4","2.0.0-RC3","2.0.0","v4.6.2","v4.6.1","v4.6.0","v4.5.1","2.0.0-RC2","2.0.0-RC1","1.5.0-RC6","1.5.0-RC5","1.5.0-RC4","1.5.0-RC3","1.5.0-RC2","1.5.0-RC1","1.5.0","1.4.1-RC6","1.4.1-RC5","1.4.1-RC4","v4.5.0","1.4.1-RC3","1.4.1-RC2","1.4.1-RC1","1.4.0-RC9","1.4.0-RC8","1.4.0-RC11","1.4.0-RC10","1.4.0","v4.4.4","1.4.0-RC7","1.4.0-RC6","1.4.0-RC5","1.4.0-RC4","1.4.0-RC3","1.4.0-RC2","1.4.0-RC1","v4.4.3","R1.3.3-RC5","R1.3.3-RC4","R1.3.3-RC3","R1.3.3-RC2","R1.3.3-RC1","1.3.3","v4.4.2","R1.3.2-RC8","R1.3.2-RC7","R1.3.2-RC6","R1.3.2-RC5","R1.3.2-RC4","R1.3.2-RC3","1.3.2","v4.4.1","v4.4.0","R1.3.2-RC2","R1.3.2-RC1","R1.3.1-hotfix-RC2","R1.3.1-hotfix-RC1","R1.3.1-RC5","R1.3.1-RC4","R1.3.1-RC3","R1.3.1-RC2","1.3.1.1","1.3.1","edge-R0.4.3-RC1","v4.3.0","R1.3.1-RC1","R1.3.0-RC22","R1.3.0-RC21","R1.3.0-RC20","R1.3.0-RC19","R1.3.0-RC18","R1.3.0-RC17","R1.3.0-RC16","R1.3.0-RC15","R1.3.0-LA","1.3.0-GA","1.3.0","v4.2.0","v4.1.1","R1.3.0-RC9","R1.3.0-RC8","R1.3.0-RC7","R1.3.0-RC6","R1.3.0-RC5","R1.3.0-RC4","R1.3.0-RC3","R1.3.0-RC2","R1.3.0-RC14","R1.3.0-RC13","R1.3.0-RC12","R1.3.0-RC11","R1.3.0-RC10","R1.2.6-RC9","R1.2.6-RC8","R1.2.6-RC7","R1.2.6-RC6","R1.2.6-RC5","R1.2.6-RC11","R1.2.6-RC10","R1.2.6-LA","v4.1.0","v4.0.10","RR1.2.5-RC9","RR1.2.5-RC8","RR1.2.5-RC7","RR1.2.5-RC6","RR1.2.5-RC5","RR1.2.5-RC4","RR1.2.5-RC3","RR1.2.5-RC2","RR1.2.5-RC10","RR1.2.5-RC1","RR1.2.4-RC4","RR1.2.4-RC3","RR1.2.4-RC2","RR1.2.4-RC1","RR1.2.3-RC9","RR1.2.3-RC8","RR1.2.3-RC7","RR1.2.3-RC6","RR1.2.3-RC5","RR1.2.3-RC4","RR1.2.3-RC3","RR1.2.3-RC23","RR1.2.3-RC22","RR1.2.3-RC21","RR1.2.3-RC20","RR1.2.3-RC2","RR1.2.3-RC19","RR1.2.3-RC18","RR1.2.3-RC17","RR1.2.3-RC16","RR1.2.3-RC15","RR1.2.3-RC14","RR1.2.3-RC13","RR1.2.3-RC12","RR1.2.3-RC11","RR1.2.3-RC10","R1.3.0-RC1","R1.2.6-RC4","R1.2.6-RC3","R1.2.6-RC2","R1.2.6-RC1","R1.2.5-LA","R1.2.4-LA","v4.0.9","v4.0.8","RR1.2.2-RC6","RR1.2.2-RC5","RR1.2.2-RC4","RR1.2.2-RC3","RR1.2.2-RC2","RR1.2.2-RC1","RR1.2.2-EA","v4.0.7","v4.0.6","RR1.2.1-RC7","RR1.2.1-EA","v4.0.5","v4.0.4","RR1.2.1-RC6","RR1.2.1-RC5","RR1.2.1-RC4","v4.0.3","RR1.2.1-RC3","RR1.2.1-RC2","RR1.2.1-RC1","RR1.2.0-RC9","RR1.2.0-RC8","RR1.2.0-RC7","RR1.2.0-RC6","RR1.2.0-RC5","RR1.2.0-RC4","RR1.2.0-RC3","RR1.2.0-RC2","RR1.2.0-RC11","RR1.2.0-RC10","RR1.2.0-RC1","RR1.2.0-EA","v4.0.2","v4.0.1","v4.0.0","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.9.0","v2.8.0","v2.7.7","mbed-os-5.0-rc1","v2.7.6","v2.7.5","v2.7.4","v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.0","v2.5.0","v2.2.1","v2.4.1","v2.4.0","v2.3.3","v2.3.1","v2.3.0","mbedos-2016q1-oob3","mbedos-16.03-release","mbedos-16.01-release","v2.2.11","mbedos-2016q1-oob2","v2.2.10","mbedos-2016q1-oob1","v2.2.9","v2.2.8","v2.2.7","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.0","v2.1.0","v2.0.0","v1.1.2","mbedos-release-15-11","v1.1.1","mbedos-techcon-oob2","v0.1.10","beta-release","v0.1.9","v0.1.8","v0.1.6","2.3","2.1","1.5-ap","1.11-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12887.json","vanir_signatures_modified":"2026-08-27T08:40:04Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["43935030550028460972366703954953134506","61220096632304049730327333197098972093","320150627691496278385405560211966556678","186675183860793561524494747944059615369","127642696780443805742401594398900435540","267445146679481831720080028433391405271","132521230294210119945172885974631191107","324396917462271122704704442064617277709","234437120531583315022205507252856318308","286329828605066593614177102719712564752","87207223341953997356487330374609977771","104328434877095684334150716685446685855","11868571050448402586959641459417779210","303778255609881218744778712752022328171","133750296877345554551232479333421315007","67880556997018554008829165577206203797","92692987032122039680749309224731996056","140265851728056666005343675172730879491","63562575080231242002488574039690694253","189674393307302091111541820177517511947","321512261925602967327881274626398541763","232832846557700938117508429755115702658","264196848848161220298469949354019076766","321580769388070556555594160029624143808","151078017193110762447939574449023157217","310827814389590228290459433936542736136","256787609847999624942930714634370299162","242022160026061777274533866925894108323","62689593716048945512935592775715083022","95333874303436617107207441015869479329","112609262465420033381301208320792639619","317777804957382674265651800069815716158","199703098306503844081080891371244903433","302537996041334409574073001132100991715","305499100664098600512923207251055579036"],"threshold":0.9},"id":"CVE-2020-12887-29fdbcad","signature_type":"Line","signature_version":"v1","source":"https://github.com/mjurczak/mbed-coap/commit/4647a68e364401e81dbd370728127d844f221d93","target":{"file":"source/sn_coap_parser.c"}},{"id":"CVE-2020-12887-5a783e29","signature_type":"Function","signature_version":"v1","source":"https://github.com/mjurczak/mbed-coap/commit/4647a68e364401e81dbd370728127d844f221d93","target":{"file":"source/sn_coap_parser.c","function":"sn_coap_parser_options_parse"},"deprecated":false,"digest":{"function_hash":"308725957387540955480929850339236134260","length":7512}},{"deprecated":false,"digest":{"function_hash":"245798078326036843653460174088154310762","length":815},"id":"CVE-2020-12887-aa632ee5","signature_type":"Function","signature_version":"v1","source":"https://github.com/mjurczak/mbed-coap/commit/4647a68e364401e81dbd370728127d844f221d93","target":{"file":"source/sn_coap_parser.c","function":"parse_ext_option"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}