CVE-2024-52802
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function parseadvertise, located in /sys/net/application_layer/dhcpv6/client.c, has no minimum header length check for dhcpv6optt after processing dhcpv6msgt. This omission could lead to an out-of-bound read, causing system inconsistency. Additionally, the same lack of a header length check is present in the function preparseadvertise, which is called by parseadvertise before handling the request. As of time of publication, no known patched version exists.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52802.json, https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-xgv3-pcq6-qmrg, https://nvd.nist.gov/vuln/detail/CVE-2024-52802
