CVE-2024-56319

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-56319
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-56319.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-56319
Published
2024-12-18T23:15:18Z
Modified
2025-10-21T13:27:58.288280Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).

References

Affected packages

Git / github.com/project-chip/connectedhomeip

Affected ranges

Type
GIT
Repo
https://github.com/project-chip/connectedhomeip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

SVE_23_03/rc1
SVE_23_03/rc2
SVE_23_09/rc1
TE8/rc1
TE8/rc2
TE8/rc3
TE9
TE_23_02/rc1
TE_23_02/rc2
TE_24_01/rc1
test_event_1_2012_03_05
test_event_2_2012_04_19
test_event_2_2012_04_21
test_event_2_2012_04_22
test_event_3_2012_04_21
test_event_3_2021_06_01
test_event_3_2021_06_03
test_event_4_2021_07_06
v2021_01_27-alpha
v2021_02_02-alpha
v2021_02_10-alpha

TH-Matter-1.*

TH-Matter-1.2

V1.*

V1.0.0.1

v1.*

v1.0.0.2
v1.1.0.0
v1.1.0.1
v1.2.0.0
v1.2.0.1
v1.3.0.0

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/project-chip/connectedhomeip/commit/e3277eb02ed8115de5887e8beca0e35007ba71f3",
        "id": "CVE-2024-56319-345f1806",
        "deprecated": false,
        "signature_version": "v1",
        "target": {
            "file": "src/platform/DeviceInfoProvider.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "274979859381224071766534251977082961610",
                "76670136514562615793437095870430074797",
                "198203288176832173510933779414057668246",
                "200934772411980890707925581386763924632",
                "154253142573653093311960595330795857076"
            ]
        },
        "signature_type": "Line"
    },
    {
        "source": "https://github.com/project-chip/connectedhomeip/commit/e3277eb02ed8115de5887e8beca0e35007ba71f3",
        "id": "CVE-2024-56319-4b554219",
        "deprecated": false,
        "signature_version": "v1",
        "target": {
            "function": "DeviceInfoProvider::AppendUserLabel",
            "file": "src/platform/DeviceInfoProvider.cpp"
        },
        "digest": {
            "length": 252.0,
            "function_hash": "252041815894719736757532298785361311032"
        },
        "signature_type": "Function"
    }
]