CVE-2024-3332: bt: host/smp: DoS caused by null pointer dereference
Published Jul 3, 2024
·Updated
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
Affected Software
1 affected component
zephyrproject zephyr<=3.6.0
Remediation
Event History
Jul 3, 2024
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-3332?
CVE-2024-3332 is classified as a denial-of-service (DoS) vulnerability affecting Bluetooth Low Energy (BLE) devices.
2
How does CVE-2024-3332 exploit the vulnerability?
CVE-2024-3332 allows a malicious BLE device to send a specific sequence of packets that can disrupt the normal operation of the affected BLE device.
3
What versions of Zephyr are affected by CVE-2024-3332?
CVE-2024-3332 impacts all versions of Zephyr up to and including 3.6.0.
4
How do I fix CVE-2024-3332?
To mitigate CVE-2024-3332, update your Zephyr Project software to a version newer than 3.6.0 that addresses this vulnerability.
5
What are the potential impacts of CVE-2024-3332?
The potential impact of CVE-2024-3332 is a denial-of-service condition that can render the affected BLE device inoperable.