contiki-ng BLE-L2CAP contains Improper size validation of L2CAP frames
CVE-2023-23609
8.2HIGH
What is CVE-2023-23609?
The Contiki-NG operating system, designed for Next-Generation IoT devices, is susceptible to an out-of-bounds write vulnerability in its Bluetooth Low Energy - Logical Link Control and Adaptation Layer Protocol (BLE-L2CAP) module. This issue arises when packet fragments are reassembled without verifying whether the packet buffer can accommodate the full size of the reassembled packet. Specifically, configurations prior to version 4.9 can allow an out-of-bounds write of up to 1152 bytes, which may lead to code execution or data corruption. Users are advised to patch their systems immediately, utilizing the fix available in pull request #2254 on GitHub.
Affected Version(s)
contiki-ng <= 4.8