{"id":"CVE-2026-24801","summary":"A Potential SPA-vulnerability in Ralim/IronOS","details":"Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source modules). This vulnerability is associated with program files ecc_dsa.C.\n\nThis issue affects IronOS: before v2.23-rc3.","modified":"2026-08-12T15:32:56.762217Z","published":"2026-01-27T08:36:25.407Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24801.json","cna_assigner":"GovTech CSG"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24801.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24801"},{"type":"FIX","url":"https://github.com/Ralim/IronOS/pull/2087"},{"type":"PACKAGE","url":"https://github.com/Ralim/IronOS"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ralim/ironos","events":[{"introduced":"0"},{"fixed":"d775036c9e587e063a518ca9a555c4591a7efe06"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"v2.23-rc3"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v2.23-rc2","v2.23-rc1","v2.22-rc3","v2.22","v2.22-rc2","v2.22-rc","v2.20","v2.18.2","v2.18.1","v2.18","v2.17","v2.16","v2.16-rc2","v2.16-rc","v2.15","v2.15-rc1","v2.14.1","v2.14","v2.13","v2.12-beta","v2.11","v2.10.1","v2.10","v2.09","v2.08.1","v2.08","v2.07","v2.06","v2.06-RC4","v2.06-RC3","v2.06-RC2","v2.06-RC1","v2.05.01","v2.05","v2.04.1","v2.04","v2.04-RC2","v2.04-RC1","v2.03","v2.03-RC3","v2.02","v2.01","v2.0","v1.17.1","v1.16.3","v1.16.2","v1.16.1","v1.15","v1.14","v1.13","v1.13-alpha","v1.12","v1.11.2","v1.11.1","v1.11","1.10.1","v1.10","v1.09","v1.08","v1.07","v1.06","v1.05","v1.04","V1.03","v1.02.1","v1.02","v1.01","v1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24801.json","vanir_signatures_modified":"2026-08-12T15:32:56Z","vanir_signatures":[{"id":"CVE-2026-24801-4f20aca3","signature_type":"Function","signature_version":"v1","source":"https://github.com/ralim/ironos/commit/d775036c9e587e063a518ca9a555c4591a7efe06","target":{"file":"source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source/ecc_dsa.c","function":"uECC_sign_with_k"},"deprecated":false,"digest":{"length":1425,"function_hash":"280055632776288372284613901716130291832"}},{"digest":{"line_hashes":["126010767286256237100654316433513162273","247491151070562181346948812093894219177","49765412403022994556273071122402369092","55531343040508246235259667985626136947","124845876707839708836963364657185906542","186514073613650829788803628122917566552","91082451782934131651994864009462108059","71228014830550427819084389676258659648"],"threshold":0.9},"id":"CVE-2026-24801-fe7a7db4","signature_type":"Line","signature_version":"v1","source":"https://github.com/ralim/ironos/commit/d775036c9e587e063a518ca9a555c4591a7efe06","target":{"file":"source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source/ecc_dsa.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/S:N/AU:N/R:U/V:C/RE:M/U:Red"}]}