CVE-2020-10021: Out-of-bounds write in USB Mass Storage with unaligned sizes
Published May 11, 2020
·Updated
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.
Affected Software
2 affected components
zephyrproject zephyr<=1.14.1
zephyrproject zephyr>=2.1.0<2.2.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 11, 2020
CVE Published
via MITRE·10:26 PM
Data Sourced
via MITRE·10:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-10021?
CVE-2020-10021 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-10021?
To fix CVE-2020-10021, update the Zephyr project to version 2.2.0 or later.
3
Which versions of Zephyr are affected by CVE-2020-10021?
CVE-2020-10021 affects Zephyr versions 1.14.1 and later, as well as versions 2.1.0 to 2.2.0.
4
What type of vulnerability is CVE-2020-10021?
CVE-2020-10021 is an out-of-bounds write vulnerability in the USB Mass Storage memoryWrite handler.
5
Is CVE-2020-10021 a critical vulnerability?
No, CVE-2020-10021 is not considered a critical vulnerability.