漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RIOT-OS vulnerable to null pointer dereference during fragment forwarding
Vulnerability Description
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a NULL pointer dereference. During forwarding of a fragment an uninitialized entry in the reassembly buffer is used. The NULL pointer dereference triggers a hard fault exception resulting in denial of service. Version 2022.10 fixes this issue. As a workaround, disable support for fragmented IP datagrams or apply the patches manually.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
空指针解引用
Vulnerability Title
RIOT RIOT-OS 代码问题漏洞
Vulnerability Description
RIOT RIOT-OS是一套应用于物联网领域的操作系统。 RIOT RIOT-OS 2022.10 之前版本存在代码问题漏洞,攻击者利用该漏洞可以向设备发送特制帧,导致空指针解引用,在转发片段期间,未初始化的重组缓冲区条目被使用,空指针解引用触发了硬故障异常,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A