CVE-2024-56317

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by access-control-server.cpp, i.e., a denial of service.
Configurations

No configuration.

History

02 Jan 2025, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

18 Dec 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 23:15

Updated : 2025-01-02 20:16


NVD link : CVE-2024-56317

Mitre link : CVE-2024-56317

CVE.ORG link : CVE-2024-56317


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions