First published: Sun Feb 26 2023(Updated: )
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | =2.4.0 | |
Zephyrproject Zephyr | =2.4.0-rc1 | |
Zephyrproject Zephyr | =2.4.0-rc2 | |
Zephyrproject Zephyr | =2.4.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3329 is a vulnerability in the HCI Host stack initialization of the Bluetooth stack in Zephyr Project Zephyr 2.4.0 and earlier.
The severity of CVE-2021-3329 is critical with a severity value of 6.5.
CVE-2021-3329 affects Zephyr Project Zephyr 2.4.0 and earlier versions.
CVE-2021-3329 can be exploited by causing a crash of the Bluetooth stack through lack of proper validation in HCI Host stack initialization.
Yes, a fix for CVE-2021-3329 is available. It is recommended to update to Zephyr Project Zephyr version 2.4.1 or later.