PT-2025-54430 · Libcoap+2 · Libcoap+2
Secmate
·
Published
2025-01-01
·
Updated
2026-02-24
·
CVE-2025-34468
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libcoap versions up to and including 4.3.5
Description
The software contains a stack-based buffer overflow in address resolution. This occurs when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without sufficient bounds checking. A remote attacker could potentially cause a crash and, depending on compiler settings and runtime memory protections, achieve remote code execution. Exploitation requires the proxy logic to be enabled, specifically the proxy request handling code path within an application utilizing libcoap.
Recommendations
Update libcoap to a version prior to 4.3.5 that includes commit 30db3ea.
Fix
DoS
RCE
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Red Os
Libcoap