The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure, allowing attackers in radio range to immediately crash (and restart) a device via a crafted LMP packet.
Link | Tags |
---|---|
http://www.zh-jieli.com/product/68-cn.html | product vendor advisory |
https://launchstudio.bluetooth.com/ListingDetails/58628 | third party advisory |
https://launchstudio.bluetooth.com/ListingDetails/19746 | third party advisory |
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf | third party advisory technical description |