PT-2022-23033 · Unknown · Contiki-Ng

Joakimeriksson

·

Published

2022-08-04

·

Updated

2022-08-11

·

CVE-2022-35927

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contiki-NG versions prior to 4.7
Description The issue is related to the RPL-Classic routing protocol implementation in the Contiki-NG operating system. Specifically, an incoming DODAG Information Option (DIO) control message can contain a prefix information option with a length parameter that is not validated. This can cause a buffer overflow when copying the prefix in the set ip from prefix function. The estimated number of potentially affected devices is not provided, and there is no information about real-world incidents where this issue was exploited.
Recommendations To resolve the issue, users should upgrade to Contiki-NG 4.7 or later. As a temporary workaround, consider restricting the reception of RPL DIO messages from external parties until a patched version is installed. There are no other workarounds for this issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-35927
GHSA-9RM9-3PHH-P4WM

Affected Products

Contiki-Ng