RIOT-OS vulnerable to Out of Bounds write in routing with SRH
CVE-2023-24817
7.5HIGH
What is CVE-2023-24817?
A vulnerability in the network stack of RIOT-OS prior to version 2023.04 allows an attacker to manipulate 6LoWPAN frame processing, potentially leading to an integer underflow and out-of-bounds access in the packet buffer. Successfully exploiting this issue can result in packet corruption and denial of service by disrupting the underlying memory management. Users are advised to update to version 2023.04 or implement a workaround by disabling SRH in the network stack to bolster security.
Affected Version(s)
RIOT < 2023.04