In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen).
CVE ID: CVE-2025-32366
CVSS Base Severity: LOW
CVSS Base Score: 3.7
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Vendor: ConnMan
Product: ConnMan
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 18.69% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)