CVE-2024-3077: Bluetooth: integer underflow in gatt_find_info_rsp
Published Mar 29, 2024
·Updated
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
Affected Software
1 affected component
zephyrproject zephyr<=3.6.0
Remediation
Event History
Mar 29, 2024
CVE Published
via MITRE·05:06 AM
Data Sourced
via MITRE·05:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3077?
CVE-2024-3077 is classified as a critical vulnerability due to its potential to cause denial of service through a crash of the affected device.
2
How does CVE-2024-3077 affect BLE devices?
CVE-2024-3077 allows a malicious BLE device to send malformed GATT packets that can crash a vulnerable BLE victim device.
3
What versions of Zephyr are vulnerable to CVE-2024-3077?
CVE-2024-3077 affects Zephyr versions up to and including 3.6.0.
4
How do I mitigate the risk of CVE-2024-3077?
To mitigate CVE-2024-3077, it is recommended to upgrade to a fixed version of Zephyr beyond 3.6.0.
5
What should I do if my device is affected by CVE-2024-3077?
If your device is affected by CVE-2024-3077, you should immediately review upgrade options to a secure version of Zephyr.