First published: Tue Aug 30 2022(Updated: )
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek Bluetooth Mesh Software Development Kit | <=4.17-4.17-20220127 | |
Google Android | ||
Linux Linux kernel |
Realtek Linux/Android Bluetooth Mesh SDK v4.18-4.18-20220218
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25635 is a buffer overflow vulnerability in Realtek Linux/Android Bluetooth Mesh SDK.
The severity of CVE-2022-25635 is medium with a CVSS score of 6.5.
CVE-2022-25635 affects Realtek Bluetooth Mesh Software Development Kit with versions up to and including 4.17-4.17-20220127.
An unauthenticated attacker in the adjacent network can exploit CVE-2022-25635 to disrupt service.
You can find more information about CVE-2022-25635 at the following link: [https://www.twcert.org.tw/tw/cp-132-6456-fc6c5-1.html](https://www.twcert.org.tw/tw/cp-132-6456-fc6c5-1.html)