The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bluez | Mar 21, 2024 | Jun 9, 2021 |
| Debian | — | Upgrade bluez | Jul 30, 2024 | Jun 10, 2021 |
| Gentoo Linux | — | Upgrade net-wireless/bluez. | Sep 30, 2022 | Jun 10, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 10, 2021 |
| Suse | — | Upgrade bluez-zsh-completionUpgrade libbluetooth3-32bitUpgrade bluezUpgrade bluez-auto-enable-devicesUpgrade bluez-testUpgrade bluez-develUpgrade bluez-cupsUpgrade bluez-deprecatedUpgrade bluez-devel-32bitUpgrade libbluetooth3 | Jul 23, 2021 | Jun 10, 2021 |
| Ubuntu | — | Upgrade bluezUpgrade libbluetooth3 | Jun 17, 2021 | Jun 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub