important · Bluetooth — Zephyr
An unauthenticated Bluetooth Classic peer can inject data into Zephyr L2CAP handlers before authentication completes.
Affects
Zephyr, an embedded real-time operating system used in connected devices
While a dynamic channel is still half-open, Zephyr can resolve its destination CID and dispatch attacker-controlled data without requiring the CONNECTED state.
Detail and 3 sources
A fix is published, but its effect was not assessed here and no public proof or independent reproduction was located.
Sources
Code / PoCMissing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path · Advisory · zephyrproject-rtos/zephyr · GitHubPatchbluetooth: classic: l2cap: add state validation in receive path · zephyrproject-rtos/zephyr@2738ee9 · GitHubSecondaryRelease Zephyr 4.4.2 · zephyrproject-rtos/zephyr