High severity7.0NVD Advisory· Published Jun 18, 2021· Updated Jun 17, 2026
CVE-2021-21281
CVE-2021-21281
Description
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a packet with a data offset that is unvalidated. The problem has been patched in Contiki-NG 4.6. Users can apply the patch for this vulnerability out-of-band as a workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:contiki-ng:contiki-ng:*:*:*:*:*:*:*:*range: <4.6
- (no CPE)range: < 4.6
- Range: <4.6
Patches
Vulnerability mechanics
References
2- github.com/contiki-ng/contiki-ng/pull/1366nvdPatchThird Party Advisory
- github.com/contiki-ng/contiki-ng/security/advisories/GHSA-mc42-fqfr-h9fpnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.