Security Advisory

CVE-2021-3861

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-02-07 22:00:13
Last updated 2024-09-16 16:18:17
Assigner zephyr
CVSS score 8.2
State PUBLISHED

Description

The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj