PT-2022-10334 · Zephyr · Zephyr

Bronallo-Bd

+1

·

Published

2022-06-28

·

Updated

2023-06-26

·

CVE-2021-3433

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Zephyr versions >= v2.5.0
Description The issue arises from an invalid channel map in CONNECT IND, resulting in a deadlock due to improper check or handling of exceptional conditions. This is classified as CWE-703.
Recommendations For Zephyr versions >= v2.5.0, consider temporarily disabling the CONNECT IND functionality until a patch is available to prevent deadlocks caused by invalid channel maps. Restrict access to the vulnerable module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2021-3433
GHSA-3C2F-W4V6-QXRP

Affected Products

Zephyr