The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.
Link | Tags |
---|---|
https://www.ti.com/tool/CC256XC-BT-SP#primary-sw | product vendor advisory |
https://www.ti.com/product/CC2564C | product vendor advisory |
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf | third party advisory technical description |