CVE Vulnerabilities

CVE-2021-31400

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Aug 19, 2021 | Modified: Aug 26, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segments data. If the panic function hadnt a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset).

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Nichestack Hcc-embedded * 4.3 (excluding)

References