CVE-2022-26529: Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Published Aug 30, 2022
·Updated
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
Affected Software
3 affected components
Realtek Bluetooth Mesh Software Development Kit<=4.17-4.17-20220127
Google Android
Linux Linux Kernel
Remediation
Information
Realtek Linux/Android Bluetooth Mesh SDK v4.18-4.18-20220218
Event History
Aug 30, 2022
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-26529?
CVE-2022-26529 is a buffer overflow vulnerability in Realtek Linux/Android Bluetooth Mesh SDK.
2
What is the severity of CVE-2022-26529?
The severity of CVE-2022-26529 is medium with a severity value of 6.5.
3
How does CVE-2022-26529 affect Realtek Bluetooth Mesh Software Development Kit?
CVE-2022-26529 affects Realtek Bluetooth Mesh Software Development Kit version 4.17-4.17-20220127.
4
What can an unauthenticated attacker do with CVE-2022-26529?
An unauthenticated attacker in the adjacent network can exploit CVE-2022-26529 to cause buffer overflow and disrupt service.
5
Is Google Android or Linux Linux kernel vulnerable to CVE-2022-26529?
No, Google Android and Linux Linux kernel are not vulnerable to CVE-2022-26529.