CVE-2025-36939: Buffer Overflow
Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
Who can exploit these issues?
An attacker must be authenticated and connected to the same Thread network as the affected OpenThread deployment. The available information does not indicate that an attacker can exploit the issue remotely without Thread-network access.
What impact can exploitation have?
Specially crafted MLE packets can trigger assertion failures or a stack-based buffer overflow. The described impact includes denial of service.
What traffic should defenders focus on when investigating possible exploitation?
Focus on MLE packet traffic originating from authenticated devices on the local Thread network, particularly malformed or specially crafted packets. The provided information does not include specific packet signatures, logging indicators, or detection rules.