![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-6258 – BT: Missing length checks of net_buf in rfcomm_handle_data
https://notcve.org/view.php?id=CVE-2024-6258
13 Sep 2024 — BT: Missing length checks of net_buf in rfcomm_handle_data • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7833-fcpm-3ggm • CWE-20: Improper Input Validation CWE-122: Heap-based Buffer Overflow CWE-191: Integer Underflow (Wrap or Wraparound) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-5754 – BT: Encryption procedure host vulnerability
https://notcve.org/view.php?id=CVE-2024-5754
13 Sep 2024 — BT: Encryption procedure host vulnerability • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gvv5-66hw-5qrc • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-4785 – BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
https://notcve.org/view.php?id=CVE-2024-4785
19 Aug 2024 — BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xcr5-5g98-mchp • CWE-20: Improper Input Validation CWE-369: Divide By Zero •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-3332 – bt: host/smp: DoS caused by null pointer dereference
https://notcve.org/view.php?id=CVE-2024-3332
03 Jul 2024 — A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-jmr9-xw2v-5vf4 • CWE-476: NULL Pointer Dereference •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-3077 – Bluetooth: integer underflow in gatt_find_info_rsp
https://notcve.org/view.php?id=CVE-2024-3077
29 Mar 2024 — An malicious BLE device can crash BLE victim device by sending malformed gatt packet Un dispositivo BLE malicioso puede bloquear el dispositivo víctima de BLE al enviar un paquete gatt con formato incorrecto • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gmfv-4vfh-2mh8 • CWE-126: Buffer Over-read CWE-190: Integer Overflow or Wraparound •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-7060 – Missing Security Control in Zephyr OS IP Packet Handling
https://notcve.org/view.php?id=CVE-2023-7060
15 Mar 2024 — Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address. El manejo de paquetes IP de Zephyr OS no descarta adecuadamente los paquetes IP que llegan a una interfaz externa con una dirección de origen igual a 127.0.01 o la dirección de destino. • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fjc8-223c-qgqr •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-6881 – fs: fuse: buffer overflow vulnerability in the Zephyr FS
https://notcve.org/view.php?id=CVE-2023-6881
20 Feb 2024 — Possible buffer overflow in is_mount_point Posible desbordamiento de búfer en is_mount_point • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mh67-4h3q-p437 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2024-1638 – Bluetooth characteristic LESC security requirement not enforced without additional flags
https://notcve.org/view.php?id=CVE-2024-1638
19 Feb 2024 — The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined with other permissions, namely BT_GATT_PERM_READ_ENCRYPT/BT_GATT_PERM_READ_AUTHEN (for read) or BT_GATT_PERM_WRITE_ENCRYPT/BT_GATT_PERM_WRITE_AUTHEN (for write), if these additional permissions... • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p6f3-f63q-5mc2 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-5779 – can: out of bounds in remove_rx_filter function
https://notcve.org/view.php?id=CVE-2023-5779
18 Feb 2024 — can: out of bounds in remove_rx_filter function puede: fuera de los límites en la función remove_rx_filter • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7cmj-963q-jj47 • CWE-787: Out-of-bounds Write •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-6249 – ipm: signed to unsigned conversion problem in esp32_ipm_send
https://notcve.org/view.php?id=CVE-2023-6249
18 Feb 2024 — Signed to unsigned conversion esp32_ipm_send Conversión firmada a no firmada esp32_ipm_send • https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-32f5-3p9h-2rqc • CWE-704: Incorrect Type Conversion or Cast •