CVE-2021-3432: BT: Invalid interval in CONNECT_IND leads to Division by Zero
Published Jun 28, 2022
·Updated
Invalid interval in CONNECTIND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4
Affected Software
1 affected component
zephyrproject zephyr>=1.14.0<2.6.0
Event History
Jun 28, 2022
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3432?
CVE-2021-3432 is a vulnerability in Zephyr versions >= v1.14.0 that leads to a Division by Zero (CWE-369).
2
How severe is CVE-2021-3432?
CVE-2021-3432 has a severity value of 7.5 (high).
3
Which software versions are affected by CVE-2021-3432?
Zephyr versions >= v1.14.0 and <= v2.6.0 are affected by CVE-2021-3432.
4
How can I fix CVE-2021-3432?
To fix CVE-2021-3432, it is recommended to upgrade Zephyr to a version higher than v2.6.0.
5
Where can I find more information about CVE-2021-3432?
For more information about CVE-2021-3432, you can visit the Zephyr GitHub page: http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4.