CVE-2021-3510: Zephyr JSON decoder incorrectly decodes array of array
Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch GHSA-289f-7mw3-2qf4
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3510.
What is the severity of CVE-2021-3510?
The severity of CVE-2021-3510 is high.
What software versions are affected by CVE-2021-3510?
Zephyr versions >=1.14.0 and >=2.5.0 are affected by CVE-2021-3510.
What is the CWE ID associated with CVE-2021-3510?
The CWE ID associated with CVE-2021-3510 is CWE-588.
Where can I find more information about CVE-2021-3510?
You can find more information about CVE-2021-3510 at the following link: http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4