CVE-2023-0396: Buffer Overreads in Bluetooth HCI
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0396?
CVE-2023-0396 is a vulnerability related to a malicious or defective bluetooth controller that can cause buffer overreads in the most functions that process HCI command responses.
What software is affected by CVE-2023-0396?
Zephyrproject Zephyr versions up to and including 3.2.0 are affected by CVE-2023-0396.
What is the severity of CVE-2023-0396?
CVE-2023-0396 has a severity rating of medium with a CVSS score of 6.8.
How can a malicious bluetooth controller exploit CVE-2023-0396?
A malicious or defective bluetooth controller can exploit CVE-2023-0396 by causing buffer overreads in the functions that process HCI command responses, potentially leading to unauthorized access or denial of service.
Where can I find more information about CVE-2023-0396?
You can find more information about CVE-2023-0396 in the Zephyrproject Zephyr security advisory available at: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8rpp-6vxq-pqg3