yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-28488
Component Overview
Vulnerability Overview
Name
CVE-2023-28488
Source
NVD (
link
)
Debian (
link
)
Description
client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
CWEs
CWE-787
Published Date
Apr 12, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/moehw/poc_exploits/tree/master/CVE-2023-28488
Exploit
https://kernel.googlesource.com/pub/scm/network/connman/connman/+/99e2c16ea1cced34a5dc450d76287a1c3e762138
Patch
https://github.com/moehw/poc_exploits/tree/master/CVE-2023-28488
Exploit
https://kernel.googlesource.com/pub/scm/network/connman/connman/+/99e2c16ea1cced34a5dc450d76287a1c3e762138
Patch
Analysis
#
Affected Component
Analysis
connman
Patched
Vulnerability Ratings
#
6.5
CVSSv31
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
connman
buildroot
2025.02.x
1.45
Not Affected
connman
buildroot
master
2.0
Not Affected
connman
yocto
master
2.0
Not Affected
connman
yocto
scarthgap
1.42
Not Affected
Resolved with patches
#
connman (yocto:kirkstone)
#
Title
Author
Resolve
1
gdhcp: Verify and sanitize packet length first
Daniel Wagner <wagi@monom.org>
CVE-2023-28488