Hi, Please find attached a security advisory that describes multiple vulnerabilities we discovered in RIOT OS. * Title: Multiple vulnerabilities in RIOT OS * OS: RIOT <= 2024.01 * Author: Marco Ivaldi <marco.ivaldi () hnsecurity it> * Date: 2024-05-07 * CVE ID and severity: * CVE-2024-31225 - High * CVE-2024-32017 - Critical * CVE-2024-32018 - High (low-severity vulnerabilities were not assigned a CVE ID) * Vendor URL: https://www.riot-os.org/ * Advisory URLs: * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-2572-7q7c-3965 * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-v97j-w9m6-c4h3 * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-899m-q6pp-hmp3 * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x3j5-hfrr-5x6q * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-pw2r-pp35-xfmj * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-c4p4-vv7v-3hx8 * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-r87w-9vw9-f7cx * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-2hx7-c324-3rxv * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-frp5-4gfp-84j3 * https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x27v-gqp4-7jq3 The advisory is also available at: https://github.com/hnsecurity/vulns/blob/main/HNS-2024-07-riot.txt For additional information, please refer to our vulnerability writeup: https://security.humanativaspa.it/multiple-vulnerabilities-in-riot-os/ Regards, -- Marco Ivaldi https://0xdeadbeef.info/ "When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl."
Attachment:
HNS-2024-07-riot.txt
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/