Out-of-bounds reads in RPL-Lite implementation in Contiki-NG operating system
CVE-2023-50927
What is CVE-2023-50927?
The Contiki-NG operating system, designed for Next-Generation IoT devices, is vulnerable due to out-of-bounds read conditions stemming from inadequate management of message lengths in its RPL-Lite protocol implementation. Attackers can exploit this vulnerability by manipulating DIO and DAO messages, particularly with RPL sub-option headers. Users are recommended to upgrade to Contiki-NG 4.9 where this issue has been addressed. Users who are unable to upgrade should consider applying the changes from PR #2484 manually to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
contiki-ng < 4.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
