PT-2022-26106 · Unknown · Contiki-Ng

Diff-Fusion

+2

·

Published

2022-11-11

·

Updated

2022-11-18

·

CVE-2022-41873

CVSS v3.1

4.2

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contiki-NG versions prior to 4.9
Description The issue concerns an out-of-bounds read in Contiki-NG, an open-source operating system for IoT devices. It occurs while processing the L2CAP protocol in the Bluetooth Low Energy stack, where an integer truncation issue leads to an incomplete bounds check on incoming channel IDs. This allows a crafted channel ID to read and write out-of-bounds memory with attacker-controlled data. The vulnerability is related to the get channel for cid function in os/net/mac/ble/ble-l2cap.c.
Recommendations For versions prior to 4.9, apply the patch in Contiki-NG pull request 2081 on GitHub as a workaround until the official release 4.9 is available.

Exploit

Fix

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-41873
GHSA-M5CJ-FW8M-FFGF

Affected Products

Contiki-Ng