7.5

CVE-2021-3510

Zephyr JSON decoder incorrectly decodes array of array

Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zephyrproject ≫ Zephyr Version 1.14.0 Update -
Zephyrproject ≫ Zephyr Version 1.14.0 Update rc1
Zephyrproject ≫ Zephyr Version 1.14.0 Update rc2
Zephyrproject ≫ Zephyr Version 1.14.0 Update rc3
Zephyrproject ≫ Zephyr Version 1.14.1 Update -
Zephyrproject ≫ Zephyr Version 1.14.1 Update rc1
Zephyrproject ≫ Zephyr Version 1.14.1 Update rc2
Zephyrproject ≫ Zephyr Version 1.14.1 Update rc3
Zephyrproject ≫ Zephyr Version 1.14.2
Zephyrproject ≫ Zephyr Version 1.14.3 Update rc1
Zephyrproject ≫ Zephyr Version 1.14.3 Update rc2
Zephyrproject ≫ Zephyr Version 2.5.0 Update -
Zephyrproject ≫ Zephyr Version 2.5.0 Update rc1
Zephyrproject ≫ Zephyr Version 2.5.0 Update rc2
Zephyrproject ≫ Zephyr Version 2.5.0 Update rc3
Zephyrproject ≫ Zephyr Version 2.5.0 Update rc4
Zephyrproject ≫ Zephyr Version 2.5.1 Update rc1
Zephyrproject ≫ Zephyr Version 2.6.0 Update -
Zephyrproject ≫ Zephyr Version 2.6.0 Update rc1
Zephyrproject ≫ Zephyr Version 2.6.0 Update rc2
Zephyrproject ≫ Zephyr Version 2.6.0 Update rc3
Zephyrproject ≫ Zephyr Version 2.6.1 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.96% 0.58
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
vulnerabilities@zephyrproject.org 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-588 Attempt to Access Child of a Non-structure Pointer

Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption.

http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4
Patch
Third Party Advisory