First published: Thu Oct 26 2023(Updated: )
Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
<=3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5139 is a potential buffer overflow vulnerability in the Zephyr STM32 Crypto driver.
More details about CVE-2023-5139 can be found at the following link: [https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-rhrc-pcxp-4453]
CVE-2023-5139 has a severity rating of 7.8 (high).
The Zephyr STM32 Crypto driver versions up to and including 3.4.0 are affected by CVE-2023-5139.
To fix CVE-2023-5139, it is recommended to update to a version of the Zephyr STM32 Crypto driver that is not affected by the vulnerability.