RIOT-OS vulnerable to Integer Underflow during IPHC receive
CVE-2023-24820
7.5HIGH
What is CVE-2023-24820?
A vulnerability exists in the RIOT-OS network stack, which supports processing of 6LoWPAN frames. When an attacker sends a specially crafted frame to an affected device, it can trigger a significant out of bounds write beyond the packet buffer. This write operation can lead to a hard fault exception that occurs when reaching the last page of RAM. Unfortunately, this hard fault is not properly handled, effectively freezing the system and resulting in a denial of service until the device is manually reset. Users are advised to update to version 2022.10 or manually apply the available patch to mitigate this vulnerability.
Affected Version(s)
RIOT < 2022.10