CVE-2021-3322: Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr
Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p86r-gc4r-4mq3
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
zephyrproject-rtos/zephyrto a version that resolves this vulnerability.Fixed in 2.4.0Patch GHSA-p86r-gc4r-4mq3
Event History
Frequently Asked Questions
What is CVE-2021-3322?
CVE-2021-3322 is a vulnerability in Zephyr that involves unexpected pointer aliasing in IEEE 802154 fragment reassembly.
What is the severity of CVE-2021-3322?
CVE-2021-3322 has a severity level of 6.5, which is considered medium.
What software versions are affected by CVE-2021-3322?
Zephyr versions >=2.4.0 and <2.5.0 are affected by CVE-2021-3322.
What is the CWE of CVE-2021-3322?
CVE-2021-3322 has a CWE (Common Weakness Enumeration) of 476, which refers to NULL Pointer Dereference.
Where can I find more information about CVE-2021-3322?
You can find more information about CVE-2021-3322 in the Zephyr project's security advisory GHSA-p86r-gc4r-4mq3.