A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
In ascscprspadd in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
No proper validation of the length of user input in olcpindhandler in zephyr/subsys/bluetooth/services/ots/otsclient.c.
In utf8trunc in zephyr/lib/utils/utf8.c, lastbytep can point to one byte before the string pointer if the string is empty.
BT:Classic: Multiple missing buf length checks