CVE-2025-34458 Details
Description
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.
A denial-of-service vulnerability has been identified in Dire Wolf versions through 1.8, prior to commit 3658a87. The issue arises in the APRS MIC-E decoder function aprs_mic_e(), located in src/decode_aprs.c. When the application processes a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, it triggers an unhandled assertion that expects a non-empty comment. This assertion failure leads to an immediate process termination, allowing a remote, unauthenticated attacker to cause a denial-of-service by sending malformed APRS traffic.
Users can upgrade to Dire Wolf versions including commit 694c95485b21c1c22bc4682703771dec4d7a374b or later. If an immediate upgrade is not possible, the patch can be backported by applying the boundary check correction in the APRS MIC-E decoder function and then rebuilding the application. As a temporary measure, access to the KISS TCP port can be restricted to trusted clients or the KISS TCP functionality can be disabled if not needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 22, 2025CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2025-010-direwolf-stack-buffer-overflow-kiss-frame.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/wb2osz/direwolf/commit/3658a87 | [email protected] | Source CodeVendor |
| https://github.com/wb2osz/direwolf/issues/618 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/wb2osz-direwolf-reachable-assertion-dos | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wb2osz Dire Wolf | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | New CVE Received | [email protected] |
Volerion