In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4.
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11068
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11068