From 194bc9b17614b9893d8dfac1d1e91ed52dc36833 Mon Sep 17 00:00:00 2001 From: Flavio Ceolin Date: Sat, 17 Feb 2024 23:33:01 -0800 Subject: [PATCH] doc: security: cve-2023-6249 left embargo Disclose information about cve-2023-6249. Signed-off-by: Flavio Ceolin --- doc/security/vulnerabilities.rst | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/doc/security/vulnerabilities.rst b/doc/security/vulnerabilities.rst index 8242f018df48..a87b767bc235 100644 --- a/doc/security/vulnerabilities.rst +++ b/doc/security/vulnerabilities.rst @@ -1606,7 +1606,15 @@ Under embargo until 2024-01-23 CVE-2023-6249 ------------- -Under embargo until 2024-02-18 +Signed to unsigned conversion problem in esp32_ipm_send may lead to buffer overflow + +- `Zephyr project bug tracker GHSA-32f5-3p9h-2rqc + `_ + +This has been fixed in main for v3.6.0 + +- `PR 65546 fix for main + `_ CVE-2023-6749 -------------