Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10651— Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject-rtos Zephyr是zephyrproject-rtos的实时操作系统。 Zephyr Project Zephyr 4.4.0及之前版本存在安全漏洞,该漏洞源于SDP解析器中的bt_sdp_parse_attribute函数在接受包含1字节属性类型和2字节属性ID的输入缓冲区后,未验证值类型字节是否存在即无条件拉取额外字节,导致截断的3字节属性在net_buf_simple_pull中触发断言检查并引发内核崩溃,造成拒绝服务;在禁用断言的构建中,解析可能继续超出可用缓冲区

CVSS 7.1 · High EPSS 0.30% · P20

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 4.3.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10651

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)
Source: CVE Program / CVE List V5
Vulnerability Description
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type), via net_buf_simple_pull_u8(). Because net_buf_simple_pull_u8() dereferences buf->data[0] before its only bounds guard (an __ASSERT_NO_MSG that compiles out when CONFIG_ASSERT is disabled, the production default), a record of exactly three bytes (0x09 followed by a 2-byte attribute ID) causes a one-byte read past the end of the logical buffer. The parser is reachable from inbound, remote-controlled data: a Bluetooth BR/EDR peer acting as an SDP server returns discovery-response records that are stored verbatim in the client receive buffer and parsed via the public bt_sdp_get_attr()/bt_sdp_has_attr()/bt_sdp_record_parse() helpers. The over-read is bounded to a single byte that is used only as an internal length selector and is never leaked to the attacker; subsequent length checks then reject the malformed record. Realistic impact is therefore limited to an edge-case denial of service (a fault only if the record ends exactly at a mapped-memory boundary, or a deterministic assert panic when CONFIG_ASSERT=y). Affects Zephyr v4.3.0 and v4.4.0; fixed by adding sizeof(type) to the length check.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Zephyr Project Zephyr 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject-rtos Zephyr是zephyrproject-rtos的实时操作系统。 Zephyr Project Zephyr 4.4.0及之前版本存在安全漏洞,该漏洞源于SDP解析器中的bt_sdp_parse_attribute函数在接受包含1字节属性类型和2字节属性ID的输入缓冲区后,未验证值类型字节是否存在即无条件拉取额外字节,导致截断的3字节属性在net_buf_simple_pull中触发断言检查并引发内核崩溃,造成拒绝服务;在禁用断言的构建中,解析可能继续超出可用缓冲区
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 4.3.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10651

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10651

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10651 (1)

Vendor Advisories for CVE-2026-10651 (1)

Same Patch Batch · zephyrproject · 2026-06-22 · 3 CVEs total

CVE-2026-10658 7.1 HIGH Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header le
CVE-2026-10645 4.9 MEDIUM Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem imag

IV. Related Vulnerabilities

V. Comments for CVE-2026-10651

No comments yet


Leave a comment