CVE-2022-1042: Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning
Published Jul 26, 2022
·Updated
In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
Affected Software
1 affected component
zephyrproject zephyr<=3.0.0
Remediation
Event History
Jul 26, 2022
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Zephyr bluetooth mesh core stack vulnerability?
The vulnerability ID of this Zephyr bluetooth mesh core stack vulnerability is CVE-2022-1042.
2
What is the severity rating of CVE-2022-1042?
CVE-2022-1042 has a severity rating of 8.8 (high).
3
How can the out-of-bound write vulnerability in the Zephyr bluetooth mesh core stack be triggered?
The out-of-bound write vulnerability in the Zephyr bluetooth mesh core stack can be triggered during provisioning.
4
Which version of Zephyr is affected by this vulnerability?
Zephyr version up to and including 3.0.0 is affected by this vulnerability.
5
Is there a fix available for CVE-2022-1042?
Yes, a fix is available for CVE-2022-1042. Please refer to the official advisory for more information.