Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP header
CVE-2020-17529

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
9 December 2020

Summary

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.

Affected Version(s)

Apache NuttX (incubating) <= 9.1.0

Apache NuttX (incubating) 10.0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache NuttX would like to thank Forescout for reporting the issue
.