First published: Mon May 24 2021(Updated: )
FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat. Zephyr versions >= v1.14.2, >= v2.3.0 contain Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <=1.14.2 | |
Zephyrproject Zephyr | >=2.0.0<=2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13598 is a vulnerability that allows a stack-based buffer overflow when enabling long file names in FAT_FS and calling fs_stat in Zephyr versions >= v1.14.2, >= v2.3.0.
The severity of CVE-2020-13598 is high with a severity value of 7.8.
The affected software is Zephyrproject Zephyr versions >= v1.14.2, >= v2.3.0.
The CWE of CVE-2020-13598 is CWE-121.
To fix CVE-2020-13598, update to a version of Zephyr that is not affected by the vulnerability.