CVE Vulnerabilities

CVE-2024-3077

Buffer Over-read

Published: Mar 29, 2024 | Modified: Jan 23, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An malicious BLE device can crash BLE victim device by sending malformed gatt packet

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject * 3.6.0 (including)

References