Source |
CVE Liste |
Identifiant |
6666258 |
Date de publication |
2022-09-01 12:15:10 (vue: 2022-09-01 15:06:50) |
Titre |
CVE-2022-36053 |
Texte |
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 network stack of Contiki-NG has a buffer module (os/net/ipv6/uipbuf.c) that processes IPv6 extension headers in incoming data packets. As part of this processing, the function uipbuf_get_next_header casts a pointer to a uip_ext_hdr structure into the packet buffer at different offsets where extension headers are expected to be found, and then reads from this structure. Because of a lack of bounds checking, the casting can be done so that the structure extends beyond the packet's end. Hence, with a carefully crafted packet, it is possible to cause the Contiki-NG system to read data outside the packet buffer. A patch that fixes the vulnerability is included in Contiki-NG 4.8. |
Notes |
|
Envoyé |
Oui |
Condensat |
2022 36053 are because beyond bounds buffer can carefully casting casts cause checking contiki crafted cross cve data devices different done end expected ext extends extension fixes found from function generation get has hdr header headers hence included incoming iot ipv6 lack low module network next offsets open operating os/net/ipv6/uipbuf outside packet packets part patch platform pointer possible power processes processing read reads source stack structure system then uip uipbuf vulnerability where |
Tags |
Vulnerability
|
Stories |
|
Move |
|