PT-2024-35453 · Riot · Riot
Ekleezg
·
Published
2024-11-22
·
Updated
2025-09-04
·
CVE-2024-52802
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RIOT versions 2024.04 and prior
Description
The issue is related to the
parse advertise function, located in /sys/net/application layer/dhcpv6/client.c, which lacks a minimum header length check for dhcpv6 opt t after processing dhcpv6 msg t. This could lead to an out-of-bound read, causing system inconsistency. The same issue is present in the preparse advertise function, which is called by parse advertise before handling the request.Recommendations
For versions 2024.04 and prior, as a temporary workaround, consider disabling the
parse advertise function until a patch is available. Restrict access to the /sys/net/application layer/dhcpv6/client.c module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Riot