CVE-2023-0397: DoS: Invalid Initialization in le_read_buffer_size_complete
Published Jan 19, 2023
·Updated
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in lereadbuffersizecomplete.
Affected Software
1 affected component
zephyrproject zephyr<=3.2.0
Event History
Jan 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this bluetooth controller vulnerability?
The vulnerability ID is CVE-2023-0397.
2
What is the severity level of CVE-2023-0397?
The severity level of CVE-2023-0397 is critical.
3
Which software is affected by CVE-2023-0397?
Zephyrproject Zephyr versions up to and including 3.2.0 are affected by CVE-2023-0397.
4
What is the impact of CVE-2023-0397?
A malicious or defective bluetooth controller can cause a Denial of Service (DoS) due to unchecked input in le_read_buffer_size_complete.
5
Is there a fix available for CVE-2023-0397?
Yes, please refer to the advisory for information on fixing CVE-2023-0397: [Link](https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-wc2h-h868-q7hj)