CVE-2021-3861

Source
https://cve.org/CVERecord?id=CVE-2021-3861
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3861.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3861
Downstream
Related
  • GHSA-hvfp-w4h8-gxvj
Published
2022-02-07T22:15:08.423Z
Modified
2026-03-13T21:59:32.634003Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3861.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "2.6.0"
            },
            {
                "last_affected": "2.7.1"
            }
        ]
    }
]