CVE-2021-3319: DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses
Published Oct 5, 2021
·Updated
DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Pointer Dereference (CWE-476), Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94jg-2p6q-5364
Affected Software
1 affected component
zephyrproject zephyr>=2.4.0<2.5.0
Event History
Oct 5, 2021
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3319?
The severity of CVE-2021-3319 is critical.
2
What is the vulnerability type of CVE-2021-3319?
CVE-2021-3319 is a Denial of Service (DOS) vulnerability.
3
Which software versions are affected by CVE-2021-3319?
Zephyr versions >=2.4.0 and <2.5.0 are affected by CVE-2021-3319.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2021-3319?
CVE-2021-3319 is associated with CWE-476 and CWE-588.
5
Where can I find more information about CVE-2021-3319?
You can find more information about CVE-2021-3319 on the GitHub Security Advisory page: http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94jg-2p6q-5364