From f0c053c0ada34714b386d6746be8bb202d41904b Mon Sep 17 00:00:00 2001 From: Flavio Ceolin Date: Mon, 19 Aug 2024 14:58:38 -0700 Subject: [PATCH] doc: security: Disclose CVE-2024-4785 Disclose information about published CVE. Signed-off-by: Flavio Ceolin --- doc/security/vulnerabilities.rst | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/doc/security/vulnerabilities.rst b/doc/security/vulnerabilities.rst index 14ba12e264c..27306d487ef 100644 --- a/doc/security/vulnerabilities.rst +++ b/doc/security/vulnerabilities.rst @@ -1732,7 +1732,15 @@ This has been fixed in main for v3.7.0 CVE-2024-4785 ------------- -Under embargo until 2024-08-07 +Bluetooth: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero + +- `Zephyr project bug tracker GHSA-xcr5-5g98-mchp + `_ + +This has been fixed in main for v3.7.0 + +- `PR 72608 fix for main + `_ CVE-2024-5754 -------------