Infinite loop in OpenWrt - #VU50245

 

Infinite loop in OpenWrt - #VU50245

Published: February 2, 2021


Vulnerability identifier: #VU50245
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing IPv6 packets on point-to-point links in netifd and odhcp6c packages. A remote attacker can send a specially crafted packet and and cause denial of service conditions.


Affected software

OpenWrt

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins