Logo
vulnerabilityCVE-2025-34450
Name
CVE-2025-34450
Source
NVD ( link)Debian ( link)
Description
merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vulnerability in the function parse_rfraw() located in src/rfraw.c. When processing crafted or excessively large raw RF input data, the application may write beyond the bounds of a stack buffer, resulting in memory corruption or a crash. This vulnerability can be exploited to cause a denial of service and, under certain conditions, may be leveraged for further exploitation depending on the execution environment and available mitigations.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
rtl_433
Patched

Vulnerability Ratings#


6.9
CVSSv4
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
23.11
Patched
openwrt
master
25.02-r1
Exploitable
openwrt
openwrt-25.12
25.02-r1
Exploitable

Resolved with patches#


rtl_433 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix overflow in rfraw test data parsing (closes #3375)
"Christian W. Zuckschwerdt" <christian@zuckschwerdt.org>
CVE-2025-34450

rtl_433 (buildroot:master)

#
Title
Author
Resolve
1
Fix overflow in rfraw test data parsing (closes #3375)
"Christian W. Zuckschwerdt" <christian@zuckschwerdt.org>
CVE-2025-34450