The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer.
The product writes data past the end, or before the beginning, of the intended buffer.
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
Link | Tags |
---|---|
https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xvvm-8mcm-9cq3 | vendor advisory |