CVE-2021-3435: L2CAP: Information leakage in le_ecred_conn_req()
Published Jun 28, 2022
·Updated
Information leakage in leecredconnreq(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
Affected Software
1 affected component
zephyrproject zephyr>=2.4.0<2.6.0
Event History
Jun 28, 2022
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-3435?
The severity of CVE-2021-3435 is medium with a severity value of 3.3.
2
What is CVE-2021-3435?
CVE-2021-3435 is an information leakage vulnerability in le_ecred_conn_req() in Zephyr versions >= v2.4.0.
3
Which software versions are affected by CVE-2021-3435?
Zephyr versions between 2.4.0 and 2.6.0 are affected by CVE-2021-3435.
4
How can I fix CVE-2021-3435?
Apply the necessary patches or updates provided by Zephyrproject to fix CVE-2021-3435.
5
Where can I find more information about CVE-2021-3435?
You can find more information about CVE-2021-3435 at http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh.