CVE-2021-3510
NixOS vulnerability analysis and mitigation

Overview

The Zephyr JSON decoder contains a vulnerability (CVE-2021-3510) that incorrectly decodes array of array structures. This vulnerability affects Zephyr versions >= 1.14.0 and >= 2.5.0, and was discovered on June 20, 2020. The issue specifically occurs when using JSONOBJDESCRARRAYARRAY, where the decoder incorrectly handles subarray token types and object assignments (Zephyr Advisory).

Technical details

When processing array structures, the vulnerability manifests in the arrparse function where it incorrectly handles token types. Specifically, when the subarray has the token type JSONTOKLISTSTART, it erroneously assigns to the object part of the union. The arr_parse function then takes the offset of the array-object, treating it as relative to the parent object, and stores the subarray length in an incorrect location. This results in the subarray length being stored where the name-pointer of the first element should be (Zephyr Advisory). The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (High), with attack vector: Network, attack complexity: Low, privileges required: None, user interaction: None (AttackerKB).

Impact

The vulnerability affects the availability of the system, with no direct impact on confidentiality or integrity. The incorrect handling of array structures could lead to potential denial of service conditions (Zephyr Advisory).

Mitigation and workarounds

The vulnerability has been patched in multiple versions: Fixed on master in version 2.7.0 (PR #36340), Fixed on v2.6.0 (PR #37816), with fixes pending for v2.5.0 and v1.14. Users are advised to upgrade to patched versions (Zephyr Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox_esr
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox-esr
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • thunderbird
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management