Buffer Overflow Vulnerability in RIOT-OS Affecting Networking Functionality
CVE-2021-27698
9.8CRITICAL
What is CVE-2021-27698?
RIOT-OS 2021.01 is impacted by a buffer overflow vulnerability located in the /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c file. This vulnerability is triggered through the _parse_options() function, which can lead to potential exploitation affecting the networking capabilities of devices running this version. Properly parsing these control messages is crucial to ensure stable and secure routing operations.