First published: Mon Jun 21 2021(Updated: )
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | >=2.4.0<2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3435 is medium with a severity value of 3.3.
CVE-2021-3435 is an information leakage vulnerability in le_ecred_conn_req() in Zephyr versions >= v2.4.0.
Zephyr versions between 2.4.0 and 2.6.0 are affected by CVE-2021-3435.
Apply the necessary patches or updates provided by Zephyrproject to fix CVE-2021-3435.
You can find more information about CVE-2021-3435 at http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh.