PT-2022-23144 · Unknown · Contiki-Ng

Joakimeriksson

·

Published

2022-09-01

·

Updated

2022-09-07

·

CVE-2022-36052

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contiki-NG versions prior to 4.8
Description The 6LoWPAN implementation in Contiki-NG may cast a UDP header structure at a certain offset in a packet buffer without checking if the packet buffer is large enough to fit a full UDP header structure from the offset where the casting is made. This can cause an out-of-bounds read beyond the packet buffer. The issue affects devices running Contiki-NG that may receive 6LoWPAN packets from external parties.
Recommendations For Contiki-NG versions prior to 4.8, update to Contiki-NG version 4.8 to resolve the issue. As a temporary workaround, consider restricting the reception of 6LoWPAN packets from external parties until the update is applied.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2022-36052
GHSA-VWR8-6MQV-X7F5

Affected Products

Contiki-Ng