First published: Fri May 01 2020(Updated: )
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <=1.14.1 | |
Zephyr Project Manager | >=2.1.0<2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10021 is classified as a medium severity vulnerability.
To fix CVE-2020-10021, update the Zephyr project to version 2.2.0 or later.
CVE-2020-10021 affects Zephyr versions 1.14.1 and later, as well as versions 2.1.0 to 2.2.0.
CVE-2020-10021 is an out-of-bounds write vulnerability in the USB Mass Storage memoryWrite handler.
No, CVE-2020-10021 is not considered a critical vulnerability.