CVE-2020-10068: Zephyr Bluetooth DLE duplicate requests vulnerability
In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resulting in a denial of service. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10068?
CVE-2020-10068 has been classified with a severity level that indicates it can lead to a denial of service.
How do I fix CVE-2020-10068?
To mitigate CVE-2020-10068, users should upgrade to a fixed version of the Zephyr project beyond 2.2.0.
Which versions are affected by CVE-2020-10068?
CVE-2020-10068 affects Zephyr versions 1.14.0 and later, as well as versions from 2.0.0 to 2.2.0.
What impact does CVE-2020-10068 have on systems?
CVE-2020-10068 can cause systems to exhibit incorrect behavior due to processing duplicate and back-to-back Bluetooth packets.
Is there a workaround for CVE-2020-10068?
Currently, there are no official workarounds for CVE-2020-10068; upgrading is the recommended resolution.