yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-31031
Component Overview
Vulnerability Overview
Name
CVE-2024-31031
Source
NVD (
link
)
Debian (
link
)
Description
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
CWEs
CWE-190
Published Date
Apr 17, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/obgm/libcoap/issues/1351
Exploit
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LPENEJBV3KSASIYKNZAKXDAH7Q66KPYG/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUL7QDYFGEIJVO2ZSG4O5HEAWR6PFC52/
Mailing List
https://github.com/obgm/libcoap/issues/1351
Exploit
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LPENEJBV3KSASIYKNZAKXDAH7Q66KPYG/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUL7QDYFGEIJVO2ZSG4O5HEAWR6PFC52/
Mailing List
Analysis
#
Affected Component
Analysis
libcoap
Patched
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libcoap
buildroot
2025.02.x
4.3.5a
Not Affected
libcoap
buildroot
master
4.3.5b
Not Affected
libcoap
openwrt
master
4.3.0-r2
Not Affected
libcoap
openwrt
openwrt-25.12
4.3.0-r2
Not Affected
libcoap
yocto
master
4.3.5b
Not Affected
Resolved with patches
#
libcoap (yocto:scarthgap)
#
Title
Author
Resolve
1
coap_pdu.c: Fix UndefinedBehaviorSanitizer:
Jon Shallow <supjps-libcoap@jpshallow.com>
CVE-2024-31031