CVE-2020-13600: Malformed SPI in response for eswifi can corrupt kernel memory
Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13600?
CVE-2020-13600 is a vulnerability that allows a malformed SPI response for eswifi to corrupt kernel memory in Zephyr versions >= 1.14.2 and >= 2.3.0.
What is the severity of CVE-2020-13600?
CVE-2020-13600 has a severity score of 7.6, which is considered high.
What software versions are affected by CVE-2020-13600?
Zephyr versions >= 1.14.2 and >= 2.3.0 are affected by CVE-2020-13600.
What is the CWE ID of CVE-2020-13600?
CVE-2020-13600 is associated with the following CWE IDs: 119, 787, 122.
Where can I find more information about CVE-2020-13600?
More information about CVE-2020-13600 can be found at http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr.