VYPR
Unrated severityNVD Advisory· Published May 30, 2023· Updated Jan 10, 2025

RIOT-OS vulnerable to NULL pointer dereference in gnrc_pktbuf_mark

CVE-2023-24825

Description

RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device to trigger a NULL pointer dereference leading to denial of service. This issue is fixed in version 2023.04. There are no known workarounds.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.