CVE-2024-56319: High severity Matter Matter vulnerability
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).
The CVSS vector indicates the issue is remotely exploitable with low attack complexity, requires no privileges, and requires no user interaction. Exploitation consists of repeatedly appending user labels through the UserLabel cluster until resources are exhausted.
Matter/connectedhomeip (Project CHIP) deployments through version 1.4.0.0 are affected before commit e3277eb. The supplied data does not identify any configuration prerequisite beyond the presence of the vulnerable UserLabel cluster behavior.
Successful exploitation can cause a denial of service through resource exhaustion. The CVSS vector assigns impact only to availability; it does not indicate confidentiality or integrity impact.
Update to a version containing commit e3277eb02ed8115de5887e8beca0e35007ba71f3 or later. This change addresses unlimited user-label appends in the UserLabel cluster.