CyberRota Analysis
AI-GeneratedA vulnerability exists in the DTLS ClientHello parser that allows an unauthenticated peer to trigger an out-of-bounds read, potentially exposing up to 255 bytes of adjacent process memory in the outgoing ServerHello. This could lead to sensitive information disclosure over the network and may result in a denial of service on the first packet. Organizations utilizing DTLS implementations should prioritize addressing this issue to mitigate the risk of data leakage and service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first packet.