PT-2024-33315 · Arm · Mbed Os

Diff-Fusion

·

Published

2024-11-20

·

Updated

2024-11-26

·

CVE-2024-48986

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mbed OS version 6.16.0
Description An issue was discovered in the hci parsing software of Mbed OS, where it dynamically determines the length of certain hci packets by reading a byte from its header. This can lead to a buffer overflow when the subsequent write operation copies the amount of data specified in the packet header, which may exceed the allocated buffer length. The bug can be exploited for a denial of service, but it is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.
Recommendations For Mbed OS version 6.16.0, as a temporary workaround, consider restricting the use of the hci parsing software until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-48986

Affected Products

Mbed Os