CVE-2021-3966: Usb bluetooth device ACL read cb buffer overflow
Published Jan 11, 2023
·Updated
usb device bluetooth class includes a buffer overflow related to implementation of netbufaddmem.
Affected Software
1 affected component
zephyrproject zephyr<3.0.0
Event History
Jan 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-3966?
The severity of CVE-2021-3966 is critical with a severity value of 8.8.
2
What software is affected by CVE-2021-3966?
Zephyrproject Zephyr software versions up to but not including 3.0.0 are affected by CVE-2021-3966.
3
What is the vulnerability description of CVE-2021-3966?
CVE-2021-3966 is a buffer overflow vulnerability in the usb device bluetooth class due to the implementation of net_buf_add_mem.
4
How can I fix CVE-2021-3966?
To fix CVE-2021-3966, update your Zephyrproject Zephyr software to version 3.0.0 or newer.
5
Where can I find more information about CVE-2021-3966?
More information about CVE-2021-3966 can be found at the following reference: [GitHub Advisory](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hfxq-3w6x-fv2m).