diff --git a/doc/security/vulnerabilities.rst b/doc/security/vulnerabilities.rst index 2eda89e11f..468098fa0c 100644 --- a/doc/security/vulnerabilities.rst +++ b/doc/security/vulnerabilities.rst @@ -1699,3 +1699,17 @@ This has been fixed in main for v3.6.0 - `PR 69170 fix for main `_ + +CVE-2024-3077 +------------- + +Bluetooth: Integer underflow in gatt_find_info_rsp. A malicious BLE +device can crash BLE victim device by sending malformed gatt packet. + +- `Zephyr project bug tracker GHSA-gmfv-4vfh-2mh8 + `_ + +This has been fixed in main for v3.7.0 + +- `PR 69396 fix for main + `_