#VU71418 Buffer overflow in Zephyr


Published: 2023-01-23

Vulnerability identifier: #VU71418

Vulnerability risk: Low

CVSSv3.1: 6.2 [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2023-0396

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Zephyr
Operating systems & Components / Operating system

Vendor: Zephyr Project

Description

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the most functions that process HCI command responses. An attacker with physical access can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

Zephyr: 1.0.0 - 3.2.0


External links
http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8rpp-6vxq-pqg3


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability