CVE-2020-10064: Improper Input Frame Validation in ieee802154 Processing
Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10064?
CVE-2020-10064 refers to a vulnerability that exists in Zephyr versions >= v1.14.2 and >= v2.2.0, which can lead to stack-based and heap-based buffer overflow.
What is the severity of CVE-2020-10064?
CVE-2020-10064 has a severity level of 9.8 (critical).
How does CVE-2020-10064 affect Zephyr software?
CVE-2020-10064 affects Zephyr versions >= v1.14.2 and >= v2.2.0. It introduces stack-based and heap-based buffer overflow vulnerabilities.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-10064?
CVE-2020-10064 is associated with CWE-121 (Stack-based Buffer Overflow) and CWE-122 (Heap-based Buffer Overflow).
How can I get more information about CVE-2020-10064?
For more information about CVE-2020-10064, you can visit the advisory page at http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7