CVE-2025-34458

HIGH

wb2osz/direwolf <1.8 - Assertion Failure

Title source: llm
STIX 2.1

Description

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.

Scores

CVSS v4 8.7
EPSS 0.0021
EPSS Percentile 43.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (3)
wb2osz/Dire Wolf < 1.8.1
wb2osz/Dire Wolf 3658a878920803bbb69a4567579dcc4d6cb80a92
wb2osz/Dire Wolf commit 3658a87
Published Dec 22, 2025
Tracked Since Feb 18, 2026