First published: Sun Dec 15 2024(Updated: )
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <=3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8798 has been rated as a medium severity vulnerability.
To mitigate CVE-2024-8798, ensure proper validation of user input length in the affected code.
CVE-2024-8798 affects all versions of Zephyr up to and including 3.7.0.
CVE-2024-8798 impacts the Zephyr Project, specifically its Bluetooth services implementation.
Check if your system is using Zephyr version 3.7.0 or earlier, as it is susceptible to CVE-2024-8798.