CVE-2020-13603: Integer Overflow in memory allocating functions
Integer Overflow in memory allocating functions. Zephyr versions >= 1.14.2, >= 2.4.0 contain Integer Overflow or Wraparound (CWE-190). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13603?
CVE-2020-13603 is a vulnerability in Zephyr versions >= 1.14.2 and >= 2.4.0 that involves an integer overflow in memory allocating functions.
How severe is CVE-2020-13603?
CVE-2020-13603 has a severity rating of 7.8 (high).
What is the impact of CVE-2020-13603?
CVE-2020-13603 can cause an integer overflow or wraparound, which can lead to memory corruption, crashes, or other unpredictable behavior.
Which software versions are affected by CVE-2020-13603?
Zephyr versions >= 1.14.2 and >= 2.4.0 are affected by CVE-2020-13603.
How can I fix CVE-2020-13603?
To fix CVE-2020-13603, update to a version of Zephyr that is not vulnerable, such as version 2.4.1 or higher.