CVE Vulnerabilities

CVE-2021-3436

Use of Multiple Resources with Duplicate Identifier

Published: Oct 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63

Weakness

The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject 1.14.2 (including) 1.14.2 (including)
Zephyr Zephyrproject 2.4.0 (including) 2.4.0 (including)
Zephyr Zephyrproject 2.5.0 (including) 2.5.0 (including)

Potential Mitigations

References