CVE-2022-25635: Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25635?
CVE-2022-25635 is a buffer overflow vulnerability in Realtek Linux/Android Bluetooth Mesh SDK.
What is the severity of CVE-2022-25635?
The severity of CVE-2022-25635 is medium with a CVSS score of 6.5.
How does CVE-2022-25635 affect Realtek Bluetooth Mesh Software Development Kit?
CVE-2022-25635 affects Realtek Bluetooth Mesh Software Development Kit with versions up to and including 4.17-4.17-20220127.
How can an attacker exploit CVE-2022-25635?
An unauthenticated attacker in the adjacent network can exploit CVE-2022-25635 to disrupt service.
Where can I find more information about CVE-2022-25635?
You can find more information about CVE-2022-25635 at the following link: [https://www.twcert.org.tw/tw/cp-132-6456-fc6c5-1.html](https://www.twcert.org.tw/tw/cp-132-6456-fc6c5-1.html)