Vulnerabilities > CVE-2021-3455 - Use After Free vulnerability in Zephyrproject Zephyr 2.4.0/2.5.0/2.5.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Disconnecting L2CAP channel right after invalid ATT request leads freeze. Zephyr versions >= 2.4.0, >= 2.5.0 contain Use After Free (CWE-416). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7g38-3x9v-v7vp
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 10 |