First published: Fri Sep 13 2024(Updated: )
BT: Missing length checks of net_buf in rfcomm_handle_data
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6258 has been classified with a medium severity due to potential impacts on data integrity.
Fix CVE-2024-6258 by updating Zephyr to version 3.6.0 or later where the vulnerability is addressed.
CVE-2024-6258 describes missing length checks of net_buf in the rfcomm_handle_data function.
CVE-2024-6258 affects all versions of Zephyr prior to 3.6.0.
Currently, there are no documented workarounds for CVE-2024-6258; updating to a patched version is recommended.