client.c in gdhcp in ConnMan could be used by network-adjacent attackers(operating a crafted DHCP server) to cause a stack-based buffer overflow
and denial of service, terminating the connman process. (CVE-2023-28488)
- https://bugs.mageia.org/show_bug.cgi?id=31878
- https://lists.debian.org/debian-lts-announce/2023/04/msg00024.html
- https://www.cve.org/CVERecord?id=CVE-2023-28488
- 8/core/connman-1.38-2.4.mga8
Get the latest Linux and open source security news straight to your inbox.