CVE-2025-34458
Description
A flaw was found in Dire Wolf. A remote, unauthenticated attacker can exploit a reachable assertion vulnerability in the APRS MIC-E decoder. By sending a specially crafted AX.25 frame that contains a MIC-E message with an empty or truncated comment field, the attacker can cause the application to terminate. This leads to a Denial of Service (DoS), making the system unavailable.
Statement
This vulnerability is rated Important because a remote, unauthenticated attacker can cause a denial of service in Dire Wolf by sending specially crafted AX.25 frames with malformed APRS MIC-E messages. This flaw affects Dire Wolf as shipped in Fedora 42 and Fedora 43.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.