Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
CVE-2024-6258: Bluetooth: Data overflow in certain Bluetooth connections
CVE-2024-6258 · published 1 year ago
Summary
A vulnerability in some Bluetooth connections can cause data to be written to memory without limits, potentially leading to security issues. This affects devices using Bluetooth connections in certain situations, and can be mitigated by updating the affected software.
What to do
- Update zephyrproject zephyr to version 3.6.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zephyrproject | zephyr |
< 3.6.0 cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:* |
Original advisory text
BT: Missing length checks of net_buf in rfcomm_handle_data
BT: Missing length checks of net_buf in rfcomm_handle_data
References
- https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7833-fcpm-... Exploit Vendor Advisory
Severity
6.5
Medium
CVSS 3.1: 6.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
CWE-191
Timeline
Published13 Sep 2024
Updated15 Aug 2026
First seen7 Mar 2026
Sources
CVE-2024-6258 · NVD
Monitor software like this
Free during beta