RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send crafted frames to the device to trigger the usage of an uninitialized object leading to denial of service. This issue is fixed in version 2023.04. As a workaround, disable fragment forwarding or SFR.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-05-30T16:07:45.208Z

Updated: 2024-08-02T11:03:19.278Z

Reserved: 2023-01-30T14:43:33.706Z

Link: CVE-2023-24826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-05-30T17:15:09.983

Modified: 2023-06-06T16:15:39.177

Link: CVE-2023-24826

cve-icon Redhat

No data.