#VU71419 Double Free in Zephyr


Published: 2023-01-23

Vulnerability identifier: #VU71419

Vulnerability risk: Low

CVSSv3.1: 5.8 [CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2022-3806

CWE-ID: CWE-415

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Zephyr
Operating systems & Components / Operating system

Vendor: Zephyr Project

Description

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in bluetooth hci. An attacker with physical access can trigger double free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

Zephyr: 1.0.0 - 3.2.0


External links
http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-w525-fm68-ppq3


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability