CVE-2026-10641: Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfphf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cindhandle(), which assigns a per-entry counter index and calls cindhandlevalues() for each list element. cindhandlevalues() then wrote hf->indtable[index] = i without verifying that index is within the 20-element int8t indtable[] array of struct bthfphf. Because the parser places no cap on the number of +CIND: list entries, a remote Attendant Gateway (a malicious, compromised, or spoofed peer the device connects to over Bluetooth) can send a response with more than 20 recognized indicator entries and drive index arbitrarily large, writing a small attacker-positioned value past the array into adjacent struct fields (feature masks, SDP/version state, the calls[] array, work/atomic bookkeeping) and potentially beyond the static connection pool slot. This yields memory corruption and at least denial of service of the Bluetooth host, triggered by a single malformed AT response with no user interaction. The sibling consumer agindicatorhandlevalues() already performed the equivalent bounds check; this commit adds the same index >= ARRAYSIZE(hf->indtable) guard to close the gap. Affects builds with CONFIGBTHFPHF enabled; introduced with the original HFP HF CIND parser (~v1.7) and present through v4.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zephyr subsys/bluetooth/host/classic/hfp_hf.c (Bluetooth Classic HFP HF)to a version that resolves this vulnerability.Fixed in v4.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10641?
CVE-2026-10641 has a high severity score of 7.1.
How do I fix CVE-2026-10641?
To address CVE-2026-10641, update to the patched version of the Zephyr Project that resolves the out-of-bounds write issue.
What impact does CVE-2026-10641 have on my system?
CVE-2026-10641 can lead to potential crashes or unexpected behavior in applications using Bluetooth HFP due to an out-of-bounds write.
Which software is affected by CVE-2026-10641?
CVE-2026-10641 affects the Zephyr Project, specifically its Bluetooth Classic Hands-Free Profile implementation.
When was CVE-2026-10641 published?
CVE-2026-10641 was published on June 17, 2026.