CVE-2024-6444: Bluetooth: ots: missing buffer length check
Published Oct 4, 2024
·Updated
No proper validation of the length of user input in olcpindhandler in zephyr/subsys/bluetooth/services/ots/otsclient.c.
Affected Software
1 affected component
zephyrproject zephyr<=3.6.0
Event History
Oct 4, 2024
CVE Published
via MITRE·06:14 AM
Data Sourced
via MITRE·06:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6444?
CVE-2024-6444 is classified as a medium severity vulnerability due to improper validation of user input.
2
How do I fix CVE-2024-6444?
To fix CVE-2024-6444, update to a fixed version of Zephyr Project software beyond version 3.6.0.
3
What software is affected by CVE-2024-6444?
CVE-2024-6444 affects Zephyr Project software versions up to and including 3.6.0.
4
What does CVE-2024-6444 mean for users of Zephyr Project?
CVE-2024-6444 means that users of Zephyr Project should conduct an immediate review and update of their systems to mitigate potential input validation issues.
5
Are there any known exploits for CVE-2024-6444?
As of now, there are no publicly disclosed exploits directly related to CVE-2024-6444 reported.