CVE-2023-4260: Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystem
Published Sep 26, 2023
·Updated
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
Affected Software
1 affected component
zephyrproject zephyr<=3.4.0
Event History
Sep 26, 2023
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverityWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4260?
CVE-2023-4260 is a potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
2
How severe is CVE-2023-4260?
CVE-2023-4260 has a severity level of critical, with a severity value of 10.
3
Which software is affected by CVE-2023-4260?
The Zephyr project's Zephyr software up to version 3.4.0 is affected by CVE-2023-4260.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-4260?
The CWEs associated with CVE-2023-4260 are CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-120 (Buffer Copy without Checking Size of Input) and CWE-193 (Off-by-one Error).
5
How can I fix CVE-2023-4260?
To fix CVE-2023-4260, it is recommended to update the Zephyr software to a version beyond 3.4.0 or apply the vendor-provided patches or solutions.