Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zephyr
(Zephyrproject)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 88 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-10-19 | CVE-2021-3454 | Truncated L2CAP K-frame causes assertion failure. Zephyr versions >= 2.4.0, >= v.2.50 contain Improper Handling of Length Parameter Inconsistency (CWE-130), Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fx88-6c29-vrp3 | Zephyr | 7.5 | ||
2021-10-05 | CVE-2021-3581 | Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q65-5gqf-fmw5 | Zephyr | 8.8 | ||
2022-06-28 | CVE-2021-3433 | Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp | Zephyr | 3.3 | ||
2023-05-30 | CVE-2023-0779 | At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible. | Zephyr | 7.7 | ||
2023-02-26 | CVE-2021-3329 | Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack | Zephyr | 6.5 | ||
2021-10-12 | CVE-2021-3322 | Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p86r-gc4r-4mq3 | Zephyr | 6.5 | ||
2023-01-25 | CVE-2023-0396 | A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses. | Zephyr | 6.8 | ||
2023-01-25 | CVE-2022-3806 | Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer. | Zephyr | 9.8 | ||
2023-01-19 | CVE-2023-0397 | A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete. | Zephyr | 6.5 | ||
2023-01-11 | CVE-2021-3966 | usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem. | Zephyr | 8.8 |