CVE-2024-32017: Buffer overflows in RIOT

Published May 1, 2024
·
Updated

RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the gcoapdnsserverproxyget() function contains a small typo that may lead to a buffer overflow in the subsequent strcpy(). In detail, the length of the uri string is checked instead of the length of the proxy string. The gcoapforwardproxycopyoptions() function does not implement an explicit size check before copying data to the cep->reqetag buffer that is COAPETAGLENGTHMAX bytes long. If an attacker can craft input so that optlen becomes larger than COAPETAGLENGTHMAX, they can cause a buffer overflow. If the input above is attacker-controlled and crosses a security boundary, the impact of the buffer overflow vulnerabilities could range from denial of service to arbitrary code execution. This issue has yet to be patched. Users are advised to add manual bounds checking.

Affected Software

2 affected components
RIOT RIOT OS
RIOT-OS RIOT<=2024.01

Event History

May 1, 2024
CVE Published
via MITRE·06:14 AM
Data Sourced
via MITRE·06:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-32017?

CVE-2024-32017 is considered a medium to high severity vulnerability due to the potential for buffer overflow.

2

How do I fix CVE-2024-32017?

To fix CVE-2024-32017, ensure that the size checks in the gcoap_dns_server_proxy_get() function are corrected to prevent buffer overflow.

3

Which software versions are affected by CVE-2024-32017?

CVE-2024-32017 affects the RIOT operating system across various versions that implement the gcoap_dns_server_proxy_get() function.

4

What types of devices are impacted by CVE-2024-32017?

CVE-2024-32017 impacts devices utilizing the RIOT real-time operating system, which typically includes 8-bit, 16-bit, and 32-bit microcontrollers.

5

Is CVE-2024-32017 an exploit that can be remotely triggered?

Yes, CVE-2024-32017 can be exploited remotely if an attacker can send crafted packets to the gcoap_dns_server_proxy_get() function.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203