RIOT-OS vulnerable to null pointer dereference during fragment forwarding
CVE-2023-24818
7.5HIGH
What is CVE-2023-24818?
RIOT-OS, a popular operating system designed for Internet of Things (IoT) devices, has a vulnerability in its network stack that handles 6LoWPAN frames. Prior to version 2022.10, an attacker could exploit this issue by sending specially crafted frames to the device, leading to a NULL pointer dereference. This results in a hard fault exception when the system attempts to forward a fragmented packet, effectively causing a denial of service condition. Users are advised to upgrade to version 2022.10 or disable support for fragmented IP datagrams as a workaround to mitigate potential risks.
Affected Version(s)
RIOT < 2022.10