CVE-2021-3330: RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr
RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Zephyr versions >= >=2.4.0 contain Out-of-bounds Write (CWE-787). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fj4r-373f-9456
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigation for Zephyr RCE/DOS: linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list—restrict/disable processing of forged fragment lists until a fix is applied (Zephyr versions >= 2.4.0 contain the out-of-bounds write, CWE-787).
Event History
Frequently Asked Questions
What is CVE-2021-3330?
CVE-2021-3330 is a vulnerability in Zephyr that leads to linked-list corruption and a large out-of-bounds write while sorting for forged fragment lists.
What is the severity of CVE-2021-3330?
The severity of CVE-2021-3330 is rated as high, with a severity score of 8.8.
Which versions of Zephyr are affected by CVE-2021-3330?
Zephyr versions >=2.4.0 and <2.5.0 are affected by CVE-2021-3330.
What is the CWE ID associated with CVE-2021-3330?
The CWE ID associated with CVE-2021-3330 is CWE-787.
How can I get more information about CVE-2021-3330?
You can find more information about CVE-2021-3330 at the following link: [CVE-2021-3330](http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fj4r-373f-9456).