CVE-2025-34458 - CVE House
Back to Database
Status published High CVE-2025-34458

wb2osz/direwolf <= 1.8.1 Reachable Assertion DoS

Vulnerability Description

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty or truncated comment field, the application triggers an unhandled assertion checking for a non-empty comment. This assertion failure causes immediate process termination, allowing a remote, unauthenticated attacker to cause a denial of service by sending malformed APRS traffic.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34458

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Vlatko Kosturjak with Marlink Cyber

Affected Vendor

Affected Software

Dire Wolf
Vulnerable Versions:
0, 3658a878920803bbb69a4567579dcc4d6cb80a92

Timeline

Official Publish: December 22nd, 2025
Last Modified: March 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)