CVE-2021-3835: Buffer overflow in usb device class
Published Feb 7, 2022
·Updated
Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf
Affected Software
3 affected components
zephyrproject zephyr>=2.6.0<2.7.1
zephyrproject zephyr=3.0.0-rc1
zephyrproject zephyr=3.0.0-rc2
Event History
Feb 7, 2022
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3835?
CVE-2021-3835 is a vulnerability related to a buffer overflow in the USB device class in Zephyr versions >= v2.6.0.
2
What is the severity of CVE-2021-3835?
The severity of CVE-2021-3835 is high, with a severity value of 8.8.
3
How does CVE-2021-3835 impact Zephyr?
CVE-2021-3835 can lead to a heap-based buffer overflow in Zephyr versions >= v2.6.0.
4
Which software versions are affected by CVE-2021-3835?
Zephyr versions >= v2.6.0 and Zephyr 3.0.0-rc1 and 3.0.0-rc2 are affected by CVE-2021-3835.
5
How can I fix CVE-2021-3835?
To fix CVE-2021-3835, update Zephyr to a version that is not affected by the vulnerability.