PT-2024-36787 · Matter · Matter

Bob13-Matter

·

Published

2024-12-18

·

Updated

2025-01-02

·

CVE-2024-56318

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Matter (aka connectedhomeip or Project CHIP) versions 1.4.0.0 and earlier, before 27ca6ec
Description The issue is related to a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service. This occurs in the rawTCP.cpp file of the affected software.
Recommendations For Matter (aka connectedhomeip or Project CHIP) versions 1.4.0.0 and earlier, before 27ca6ec, update to a version that includes the fix for the NULL pointer dereference issue in TCPBase::ProcessSingleMessage. As a temporary workaround, consider restricting the handling of TCP packets with zero messageSize to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2024-56318

Affected Products

Matter