First published: Thu Jan 19 2023(Updated: )
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <=3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0396 is a vulnerability related to a malicious or defective bluetooth controller that can cause buffer overreads in the most functions that process HCI command responses.
Zephyrproject Zephyr versions up to and including 3.2.0 are affected by CVE-2023-0396.
CVE-2023-0396 has a severity rating of medium with a CVSS score of 6.8.
A malicious or defective bluetooth controller can exploit CVE-2023-0396 by causing buffer overreads in the functions that process HCI command responses, potentially leading to unauthorized access or denial of service.
You can find more information about CVE-2023-0396 in the Zephyrproject Zephyr security advisory available at: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8rpp-6vxq-pqg3