PT-2025-54430 · Libcoap+2 · Libcoap+2

Secmate

·

Published

2025-01-01

·

Updated

2026-02-24

·

CVE-2025-34468

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcoap versions up to and including 4.3.5
Description The software contains a stack-based buffer overflow in address resolution. This occurs when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without sufficient bounds checking. A remote attacker could potentially cause a crash and, depending on compiler settings and runtime memory protections, achieve remote code execution. Exploitation requires the proxy logic to be enabled, specifically the proxy request handling code path within an application utilizing libcoap.
Recommendations Update libcoap to a version prior to 4.3.5 that includes commit 30db3ea.

Fix

DoS

RCE

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-34468

Affected Products

Debian
Red Os
Libcoap