Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
The product uses or accesses a resource that has not been initialized.
Link | Tags |
---|---|
https://github.com/SiliconLabs/gecko_sdk/releases | patch release notes |
https://community.silabs.com/sfc/servlet.shepherd/document/download/0698Y00000Wi3HwQAJ?operationContext=S1 | vendor advisory permissions required |