CVE-2019-9183: Contiki-NG
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflow during 6LoWPAN fragment processing in the face of truncated fragments in os/net/ipv6/sicslowpan.c. This results in accesses of unmapped memory, crashing the application. An attacker can cause a denial-of-service via a crafted 6LoWPAN frame.
Affected products
- Contiki-NG Contiki-NG: up to and including 4.3
- Contiki-OS Contiki: up to and including 3.0
Published 2020-04-23. Last modified 2026-06-17.