First published: Wed Jan 11 2023(Updated: )
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3966 is critical with a severity value of 8.8.
Zephyrproject Zephyr software versions up to but not including 3.0.0 are affected by CVE-2021-3966.
CVE-2021-3966 is a buffer overflow vulnerability in the usb device bluetooth class due to the implementation of net_buf_add_mem.
To fix CVE-2021-3966, update your Zephyrproject Zephyr software to version 3.0.0 or newer.
More information about CVE-2021-3966 can be found at the following reference: [GitHub Advisory](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hfxq-3w6x-fv2m).