CVE Database
/

CVE-2025-34458

Back to search

CVE-2025-34458

Published: Dec 22, 2025

Modified: Mar 23, 2026

PUBLISHED

Description

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.

VendorProductVersions

wb2osz

Dire Wolf

affected
0 - <= 1.8.1
unaffected
3658a878920803bbb69a4567579dcc4d6cb80a92

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now