CVE-2024-32018 is a critical buffer overflow vulnerability affecting the RIOT real-time operating system. Specifically, the nimble_scanlist_update() function fails to properly validate the 'len' parameter when assertion macros are compiled out, allowing an attacker to write past the end of a fixed-length buffer. This vulnerability has a CVSS score of 9.0 (Critical) and can lead to denial of service or arbitrary code execution, with a low attack complexity and no user interaction required. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential future exploitation. Users are advised to implement manual 'len' checking as a mitigation since no patch is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2024.01CPE matchmatch criteria | cpe:2.3:o:riot-os:riot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.