Buffer Over-read Vulnerability in Contiki-NG tinyDTLS
CVE-2021-42147
9.1CRITICAL
What is CVE-2021-42147?
A buffer over-read vulnerability exists in the dtls_sha256_update function of Contiki-NG's tinyDTLS, present through the master branch version 53a0d97. This vulnerability can be exploited by remote attackers, enabling them to cause a denial of service by sending specially crafted data packets. The improper handling of these packets could lead to unintended memory access, impacting the overall reliability and performance of affected services.