Impact
In the process of setting SCAN_RSP
through the HCI command, the Zephyr Bluetooth protocol stack did not effectively check the length of the incoming HCI data. Causes memory overflow, and then the data in the memory is overwritten, and may even cause arbitrary code execution. Detailed report PDF available.
Patches
This has been fixed in:
For more information
If you have any questions or comments about this advisory:
embargo: 2021-09-04
zepsec: ZEPSEC-153
Impact
In the process of setting
SCAN_RSP
through the HCI command, the Zephyr Bluetooth protocol stack did not effectively check the length of the incoming HCI data. Causes memory overflow, and then the data in the memory is overwritten, and may even cause arbitrary code execution. Detailed report PDF available.Patches
This has been fixed in:
For more information
If you have any questions or comments about this advisory:
embargo: 2021-09-04
zepsec: ZEPSEC-153