PT-2025-52453 · Igmpproxy+1 · Igmpproxy+1

Miora-Sora

·

Published

2025-12-19

·

Updated

2025-12-19

·

CVE-2025-50681

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions igmpproxy versions prior to commit 2b30c36
Description A crafted IGMPv3 membership report packet with a malicious source address can cause a denial of service (application crash). Insufficient validation in the recv igmp() function in src/igmpproxy.c allows an invalid group record type to trigger a NULL pointer dereference when logging the address using inet fmtsrc(). This can be exploited by sending malformed multicast traffic to a host running igmpproxy, leading to a crash. The software is used in embedded networking environments and consumer-grade IoT devices to handle multicast traffic.
Recommendations Update to a version after commit 2b30c36.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-50681

Affected Products

Debian
Igmpproxy