Lucene search

K
osvGoogleOSV:ASB-A-197536150
HistoryNov 01, 2021 - 12:00 a.m.

[Crafted gatt request causes the crash of bluetooth stack]

2021-11-0100:00:00
Google
osv.dev
14
bluetooth
gatt
out of bounds
remote code execution
software security

EPSS

0.001

Percentile

20.9%

In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

0.001

Percentile

20.9%