One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 6666258
Date de publication 2022-09-01 12:15:10 (vue: 2022-09-01 15:06:50)
Titre CVE-2022-36053
Texte Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 network stack of Contiki-NG has a buffer module (os/net/ipv6/uipbuf.c) that processes IPv6 extension headers in incoming data packets. As part of this processing, the function uipbuf_get_next_header casts a pointer to a uip_ext_hdr structure into the packet buffer at different offsets where extension headers are expected to be found, and then reads from this structure. Because of a lack of bounds checking, the casting can be done so that the structure extends beyond the packet's end. Hence, with a carefully crafted packet, it is possible to cause the Contiki-NG system to read data outside the packet buffer. A patch that fixes the vulnerability is included in Contiki-NG 4.8.
Notes
Envoyé Oui
Condensat 2022 36053 are because beyond bounds buffer can carefully casting casts cause checking contiki crafted cross cve data devices different done end expected ext extends extension fixes found from function generation get has hdr header headers hence included incoming iot ipv6 lack low module network next offsets open operating os/net/ipv6/uipbuf outside packet packets part patch platform pointer possible power processes processing read reads source stack structure system then uip uipbuf vulnerability where
Tags Vulnerability
Stories
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: