Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)
Vulnerability Description
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type), via net_buf_simple_pull_u8(). Because net_buf_simple_pull_u8() dereferences buf->data[0] before its only bounds guard (an __ASSERT_NO_MSG that compiles out when CONFIG_ASSERT is disabled, the production default), a record of exactly three bytes (0x09 followed by a 2-byte attribute ID) causes a one-byte read past the end of the logical buffer. The parser is reachable from inbound, remote-controlled data: a Bluetooth BR/EDR peer acting as an SDP server returns discovery-response records that are stored verbatim in the client receive buffer and parsed via the public bt_sdp_get_attr()/bt_sdp_has_attr()/bt_sdp_record_parse() helpers. The over-read is bounded to a single byte that is used only as an internal length selector and is never leaked to the attacker; subsequent length checks then reject the malformed record. Realistic impact is therefore limited to an edge-case denial of service (a fault only if the record ends exactly at a mapped-memory boundary, or a deterministic assert panic when CONFIG_ASSERT=y). Affects Zephyr v4.3.0 and v4.4.0; fixed by adding sizeof(type) to the length check.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Zephyr Project Zephyr 输入验证错误漏洞
Vulnerability Description
zephyrproject-rtos Zephyr是zephyrproject-rtos的实时操作系统。 Zephyr Project Zephyr 4.4.0及之前版本存在安全漏洞,该漏洞源于SDP解析器中的bt_sdp_parse_attribute函数在接受包含1字节属性类型和2字节属性ID的输入缓冲区后,未验证值类型字节是否存在即无条件拉取额外字节,导致截断的3字节属性在net_buf_simple_pull中触发断言检查并引发内核崩溃,造成拒绝服务;在禁用断言的构建中,解析可能继续超出可用缓冲区
CVSS Information
N/A
Vulnerability Type
N/A