CVE-2021-3861: The RNDIS USB device class includes a buffer overflow vulnerability
Published Feb 7, 2022
·Updated
The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj
Affected Software
1 affected component
zephyrproject zephyr>=2.6.0<=2.7.1
Event History
Feb 7, 2022
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3861?
CVE-2021-3861 is a vulnerability in the RNDIS USB device class that includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 are affected.
2
What is the severity of CVE-2021-3861?
The severity of CVE-2021-3861 is high with a CVSS score of 6.8.
3
How does CVE-2021-3861 affect Zephyr versions?
CVE-2021-3861 affects Zephyr versions greater than or equal to v2.6.0.
4
What is the CWE ID for CVE-2021-3861?
CVE-2021-3861 is associated with CWE IDs 119, 787, and 122.
5
Where can I find more information about CVE-2021-3861?
You can find more information about CVE-2021-3861 at the following link: http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj