Logo
vulnerabilityCVE-2025-34468
Name
CVE-2025-34468
Source
NVD ( link)Debian ( link)
Description
libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially achieve remote code execution depending on compiler options and runtime memory protections. Exploitation requires the proxy logic to be enabled (i.e., the proxy request handling code path in an application using libcoap).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libcoap
Exploitable

Vulnerability Ratings#


8.2
CVSSv4
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.3.5a
Not Affected
buildroot
master
4.3.5b
Not Affected
openwrt
master
4.3.0-r2
Exploitable
yocto
master
4.3.5b
Not Affected
yocto
scarthgap
4.3.4
Patched

Resolved with patches#


libcoap (yocto:scarthgap)

#
Title
Author
Resolve
1
coap_address.c: Validate length of provided host name
Jon Shallow <supjps-libcoap@jpshallow.com>
CVE-2025-34468