contiki-ng BLE-L2CAP contains Improper size validation of L2CAP frames
CVE-2023-23609
What is CVE-2023-23609?
The Contiki-NG operating system, designed for Next-Generation IoT devices, is susceptible to an out-of-bounds write vulnerability in its Bluetooth Low Energy - Logical Link Control and Adaptation Layer Protocol (BLE-L2CAP) module. This issue arises when packet fragments are reassembled without verifying whether the packet buffer can accommodate the full size of the reassembled packet. Specifically, configurations prior to version 4.9 can allow an out-of-bounds write of up to 1152 bytes, which may lead to code execution or data corruption. Users are advised to patch their systems immediately, utilizing the fix available in pull request #2254 on GitHub.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
contiki-ng <= 4.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
