CVE-2023-4262: Potential buffer overflow vulnerabilities in the Zephyr Mgmt subsystem
Published Sep 26, 2023
·Updated
Possible buffer overflow in Zephyr mgmt subsystem when asserts are disabled
Other sources
Rejected reason: User data field is not attacker controlled
— NVD
Affected Software
1 affected component
zephyrproject zephyr<=3.4.0
Event History
Sep 26, 2023
CVE Published
via MITRE·06:19 PM
Rejected
via MITRE·06:19 PM
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
Description
Jul 31, 2024
Rejected
via MITRE·11:16 PM
Frequently Asked Questions
1
What is CVE-2023-4262?
CVE-2023-4262 is a vulnerability in the Zephyr mgmt subsystem that can lead to a possible buffer overflow when asserts are disabled.
2
What is the severity of CVE-2023-4262?
CVE-2023-4262 is considered critical with a severity rating of 10.
3
Which software versions are affected by CVE-2023-4262?
The Zephyr version 3.4.0 and below are affected by CVE-2023-4262.
4
How can I fix CVE-2023-4262?
To fix CVE-2023-4262, it is recommended to update Zephyr to a version that includes the necessary security patches.
5
Where can I find more information about CVE-2023-4262?
More information about CVE-2023-4262 can be found at the following link: [link](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-56p9-5p3v-hhrc)