CVE-2019-15134
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrctcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to receive in sys/net/gnrc/transportlayer/tcp/gnrctcp_eventloop.c upon receiving an ACK before a SYN.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/RIOT-OS/RIOT/pull/12001, https://github.com/RIOT-OS/RIOT/pull/12001, https://github.com/RIOT-OS/RIOT/pull/12001
