CVE-2023-24817
NixOS vulnerability analysis and mitigation

Overview

RIOT-OS, an operating system for Internet of Things (IoT) devices, was found to contain a critical vulnerability (CVE-2023-24817) in its network stack's 6LoWPAN frame processing capability. The vulnerability was discovered prior to version 2023.04 and was patched in version 2023.04. The affected component is the RPL with SRH (Source Routing Header) functionality in the network stack (GitHub Advisory).

Technical details

The vulnerability stems from an integer underflow vulnerability in the index calculation for processing the next hop from an array of addresses. When the routing header length (rh->len) is zero, the calculation can trigger an underflow, leading to an out-of-bounds access while fetching the next routing address. The issue is rated as High severity with a CVSS v3.1 base score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-191 (Integer Underflow) (GitHub Advisory, NVD).

Impact

An attacker can exploit this vulnerability by sending a crafted frame to the device, resulting in an integer underflow and out-of-bounds access in the packet buffer. When triggered at the right time, this can corrupt other packets or allocator metadata. If a pointer becomes corrupted, it can lead to a denial of service condition (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in RIOT-OS version 2023.04. For users unable to update immediately, a workaround is available by disabling SRH in the network stack (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management