PT-2024-12187 · Unknown · Contiki-Ng

Diff-Fusion

+2

·

Published

2024-11-27

·

Updated

2024-11-27

·

CVE-2023-29001

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contiki-NG (affected versions not specified)
Description The Contiki-NG operating system has an issue with its IPv6 implementation, specifically in the processing of source routing headers (SRH) in its two alternative RPL protocol implementations. This can lead to uncontrolled recursion in the tcpip ipv6 output function when receiving a packet with a next-hop address that is a local address, potentially causing a stack overflow. Attackers who can send IPv6 packets to the Contiki-NG host can trigger this issue. There are no known workarounds for this issue.
Recommendations To resolve the issue, users are advised to either apply the patch manually from Contiki-NG pull request #2264 or wait for the next release of Contiki-NG, which is expected to include the fix. As a temporary workaround, consider restricting access to the tcpip ipv6 output function in the os/net/ipv6/tcpip.c module until a patch is available.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2023-29001
GHSA-7P75-MF53-FFWM

Affected Products

Contiki-Ng