Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
Vulnerability Description
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf) and the chosen RX pool has a user_data_size smaller than 2 bytes, the segmentation counter stored in the net_buf user_data area is written out of bounds in l2cap_chan_le_recv_seg (subsys/bluetooth/host/l2cap.c). The observed effects are an AddressSanitizer abort and, without ASan, heap corruption / fatal error.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
Zephyr 缓冲区错误漏洞
Vulnerability Description
Zephyr是Zephyr开源的一个可扩展的实时操作系统 (RTOS)。 Zephyr存在缓冲区错误漏洞,该漏洞源于蓝牙主机L2CAP LE CoC SDU重组过程中2字节越界写入,可能导致远程未经身份验证的BLE对等端触发堆损坏或致命错误。
CVSS Information
N/A
Vulnerability Type
N/A