{"id":"CVE-2023-35847","details":"VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).","modified":"2026-08-12T13:32:38.544748Z","published":"2023-06-19T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35847.json","cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35847.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35847"},{"type":"FIX","url":"https://github.com/virtualsquare/picotcp/commit/eaf166009e44641e6570c576ba071217f100fd99"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/virtualsquare/picotcp","events":[{"introduced":"0"},{"fixed":"eaf166009e44641e6570c576ba071217f100fd99"}],"database_specific":{"cpe":"cpe:2.3:a:virtualsquare:picotcp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.1","2.0.0","v1.6.0","v1.5.1","v1.5.0","v1.3.0","V1.2.4","v1.2.2","v1.2.1","v1.2","sprint8","sprint7","V1.0","sprint6","sprint5","sprint4","sprint3","sprint2","sprint1","sprint0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35847.json","vanir_signatures_modified":"2026-08-12T13:32:38Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/virtualsquare/picotcp/commit/eaf166009e44641e6570c576ba071217f100fd99","target":{"file":"modules/pico_tcp.c"},"deprecated":false,"digest":{"line_hashes":["107456527686810483264036284326313557834","67464624954801547498975388067602035799","134883478032843749754712105893495330826","312067642266342291605952024407400311713","236258804348681343167448998944396968696","217412199407494023064218814098398855141","49976966158606650244438672167224984213","310817882609977841968491799396385072025","301554221740591143755799445757420250889","209777018218264718563246327226251787001","239747870450346560769062783930708107259","275490253637696517392040969470024377694"],"threshold":0.9},"id":"CVE-2023-35847-1a878a06"},{"id":"CVE-2023-35847-2a0d3ef9","signature_type":"Function","signature_version":"v1","source":"https://github.com/virtualsquare/picotcp/commit/eaf166009e44641e6570c576ba071217f100fd99","target":{"file":"modules/pico_tcp.c","function":"pico_tcp_initconn"},"deprecated":false,"digest":{"function_hash":"220776243562049812956267006101530954895","length":1579}},{"signature_version":"v1","source":"https://github.com/virtualsquare/picotcp/commit/eaf166009e44641e6570c576ba071217f100fd99","target":{"file":"modules/pico_tcp.c","function":"pico_tcp_open"},"deprecated":false,"digest":{"function_hash":"288540020976153159234040532578559914135","length":1335},"id":"CVE-2023-35847-3e197a57","signature_type":"Function"},{"source":"https://github.com/virtualsquare/picotcp/commit/eaf166009e44641e6570c576ba071217f100fd99","target":{"file":"modules/pico_tcp.c","function":"tcp_syn"},"deprecated":false,"digest":{"length":2228,"function_hash":"133399434550449773476553614049209825849"},"id":"CVE-2023-35847-8f842934","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0"}