The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bluez | Mar 21, 2024 | Jun 9, 2021 |
| Debian | — | Upgrade bluez | Jul 30, 2024 | Jun 10, 2021 |
| Gentoo Linux | — | Upgrade net-wireless/bluez. | Sep 30, 2022 | Jun 10, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 10, 2021 |
| Suse | — | Upgrade bluez-zsh-completionUpgrade bluezUpgrade bluez-auto-enable-devicesUpgrade libbluetooth3-32bitUpgrade bluez-testUpgrade bluez-cupsUpgrade bluez-deprecatedUpgrade bluez-develUpgrade libbluetooth3Upgrade bluez-devel-32bit | Jul 23, 2021 | Jun 10, 2021 |
| Ubuntu | — | Upgrade libbluetooth3Upgrade bluez | Jun 17, 2021 | Jun 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub