CVE-2023-24825: RIOT-OS vulnerable to NULL pointer dereference in gnrc_pktbuf_mark
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device to trigger a NULL pointer dereference leading to denial of service. This issue is fixed in version 2023.04. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24825?
CVE-2023-24825 has a high severity rating due to its potential to cause denial of service.
How do I fix CVE-2023-24825?
To address CVE-2023-24825, upgrade to RIOT-OS version 2023.04 or later.
What type of attack does CVE-2023-24825 involve?
CVE-2023-24825 involves an attacker sending a crafted 6LoWPAN frame to trigger a NULL pointer dereference.
Which versions of RIOT-OS are affected by CVE-2023-24825?
CVE-2023-24825 affects RIOT-OS versions prior to 2023.04.
What are the consequences of CVE-2023-24825?
The consequence of CVE-2023-24825 is a denial of service that can disrupt the operation of IoT devices running vulnerable versions of RIOT-OS.