CVE-2023-37281: Out-of-bounds read during IPHC address decompression
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various IPv6 header fields during IPHC header decompression, Contiki-NG confirms the received packet buffer contains enough data as needed for that field. But no similar check is done before decompressing the IPv6 address. Therefore, up to 16 bytes can be read out of bounds on the line with the statement memcpy(&ipaddr->u8[16 - postcount], iphcptr, postcount);. The value of postcount depends on the address compression used in the received packet and can be controlled by the attacker. As a result, an attacker can inject a packet that causes an out-of-bound read. As of time of publication, a patched version is not available. As a workaround, one can apply the changes in Contiki-NG pull request #2509 to patch the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-37281?
CVE-2023-37281 is a vulnerability in the Contiki-NG operating system for internet-of-things devices.
What is the severity of CVE-2023-37281?
The severity of CVE-2023-37281 is medium with a CVSS score of 5.3.
How does CVE-2023-37281 affect Contiki-NG?
CVE-2023-37281 affects Contiki-NG versions up to and including 4.9.
How can I fix CVE-2023-37281?
To fix CVE-2023-37281, it is recommended to update Contiki-NG to a version higher than 4.9.
Where can I find more information about CVE-2023-37281?
You can find more information about CVE-2023-37281 at the following links: [GitHub Pull Request](https://github.com/contiki-ng/contiki-ng/pull/2509) and [GitHub Security Advisory](https://github.com/contiki-ng/contiki-ng/security/advisories/GHSA-2v4c-9p48-g9pr).