CVE-2025-34458

Description

A flaw was found in Dire Wolf. A remote, unauthenticated attacker can exploit a reachable assertion vulnerability in the APRS MIC-E decoder. By sending a specially crafted AX.25 frame that contains a MIC-E message with an empty or truncated comment field, the attacker can cause the application to terminate. This leads to a Denial of Service (DoS), making the system unavailable.

Statement

This vulnerability is rated Important because a remote, unauthenticated attacker can cause a denial of service in Dire Wolf by sending specially crafted AX.25 frames with malformed APRS MIC-E messages. This flaw affects Dire Wolf as shipped in Fedora 42 and Fedora 43.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.

Frequently Asked Questions

Want to get errata notifications? Sign up here.