An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet header. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined earlier plus the header length. WsfMsgAlloc then increments this again by sizeof(wsfMsg_t). This may cause an integer overflow that results in the buffer being significantly too small to contain the entire packet. This may cause a buffer overflow of up to 65 KB . This bug is trivial to exploit for a denial of service but can generally not be exploited further because the exploitable buffer is dynamically allocated.
Metrics
Affected Vendors & Products
References
History
Mon, 25 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mbed
Mbed mbed |
|
CPEs | cpe:2.3:o:mbed:mbed:6.16.0:*:*:*:*:*:*:* | |
Vendors & Products |
Mbed
Mbed mbed |
|
Metrics |
ssvc
|
Fri, 22 Nov 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Arm
Arm mbed |
|
Weaknesses | CWE-190 | |
CPEs | cpe:2.3:o:arm:mbed:6.16.0:*:*:*:*:*:*:* | |
Vendors & Products |
Arm
Arm mbed |
|
Metrics |
cvssV3_1
|
Wed, 20 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet header. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined earlier plus the header length. WsfMsgAlloc then increments this again by sizeof(wsfMsg_t). This may cause an integer overflow that results in the buffer being significantly too small to contain the entire packet. This may cause a buffer overflow of up to 65 KB . This bug is trivial to exploit for a denial of service but can generally not be exploited further because the exploitable buffer is dynamically allocated. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-20T00:00:00
Updated: 2024-11-25T21:04:38.204Z
Reserved: 2024-10-11T00:00:00
Link: CVE-2024-48983
Vulnrichment
Updated: 2024-11-25T21:01:49.317Z
NVD
Status : Modified
Published: 2024-11-20T20:15:19.183
Modified: 2024-11-25T21:15:17.750
Link: CVE-2024-48983
Redhat
No data.