In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).
[
{
"source": "https://github.com/project-chip/connectedhomeip/commit/e3277eb02ed8115de5887e8beca0e35007ba71f3",
"id": "CVE-2024-56319-345f1806",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/platform/DeviceInfoProvider.cpp"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"274979859381224071766534251977082961610",
"76670136514562615793437095870430074797",
"198203288176832173510933779414057668246",
"200934772411980890707925581386763924632",
"154253142573653093311960595330795857076"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/project-chip/connectedhomeip/commit/e3277eb02ed8115de5887e8beca0e35007ba71f3",
"id": "CVE-2024-56319-4b554219",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "DeviceInfoProvider::AppendUserLabel",
"file": "src/platform/DeviceInfoProvider.cpp"
},
"digest": {
"length": 252.0,
"function_hash": "252041815894719736757532298785361311032"
},
"signature_type": "Function"
}
]