First published: Mon May 24 2021(Updated: )
Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | >=2.0.0<=2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3320 is a vulnerability in Zephyr versions >= v2.4.0 that allows for a NULL pointer dereference, leading to a type confusion in 802154 ACK frames handling.
The severity of CVE-2021-3320 is high, with a severity value of 7.5.
CVE-2021-3320 affects Zephyr versions >= v2.4.0, potentially leading to a NULL pointer dereference and type confusion in 802154 ACK frames handling.
To fix CVE-2021-3320, it is recommended to update Zephyr to a version that is not affected by this vulnerability.
CWE-476 is a Common Weakness Enumeration category that refers to NULL Pointer Dereference vulnerabilities.