Denial of Service Vulnerability in Contiki-NG's tinyDTLS Implementation
CVE-2021-42143
9.1CRITICAL
What is CVE-2021-42143?
An issue within the tinyDTLS implementation of Contiki-NG has been identified where an infinite loop is triggered during the processing of a ClientHello handshake message. This vulnerability allows remote attackers to exploit the system by sending specially crafted handshake messages that contain an odd length of cipher suites. The resultant infinite loop can lead to resource exhaustion, precipitating a denial of service. Additionally, the handling of such messages can also cause buffer over-reads, potentially exposing sensitive information to unauthorized entities.