CVE-2021-3329: DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
Published Feb 26, 2023
·Updated
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
Affected Software
4 affected components
zephyrproject zephyr=2.4.0
zephyrproject zephyr=2.4.0-rc1
zephyrproject zephyr=2.4.0-rc2
zephyrproject zephyr=2.4.0-rc3
Event History
Feb 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3329?
CVE-2021-3329 is a vulnerability in the HCI Host stack initialization of the Bluetooth stack in Zephyr Project Zephyr 2.4.0 and earlier.
2
What is the severity of CVE-2021-3329?
The severity of CVE-2021-3329 is critical with a severity value of 6.5.
3
How does CVE-2021-3329 affect Zephyr Project Zephyr?
CVE-2021-3329 affects Zephyr Project Zephyr 2.4.0 and earlier versions.
4
How can CVE-2021-3329 be exploited?
CVE-2021-3329 can be exploited by causing a crash of the Bluetooth stack through lack of proper validation in HCI Host stack initialization.
5
Is there a fix available for CVE-2021-3329?
Yes, a fix for CVE-2021-3329 is available. It is recommended to update to Zephyr Project Zephyr version 2.4.1 or later.