CVE-2019-15134
Published on: 08/17/2019 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:44 PM UTC
Certain versions of Riot from Riot-os contain the following vulnerability:
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to _receive in sys/net/gnrc/transport_layer/tcp/gnrc_tcp_eventloop.c upon receiving an ACK before a SYN.
- CVE-2019-15134 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 7.8 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
gnrc_tcp: Fix memory leak, potential DOS by nmeum · Pull Request #12001 · RIOT-OS/RIOT · GitHub | Exploit Patch Third Party Advisory github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Riot-os | Riot | All | All | All | All |
- cpe:2.3:o:riot-os:riot:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE