The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26896 The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
Ubuntu USN Ubuntu USN USN-4989-1 BlueZ vulnerabilities
Fixes

Solution

https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/src/gatt-database.c?id=6a50b6aeda78a88eafb177718109c256eec077a6


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2024-09-16T23:37:02.790Z

Reserved: 2021-06-08T00:00:00

Link: CVE-2021-3588

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-10T03:15:07.477

Modified: 2024-11-21T06:21:54.823

Link: CVE-2021-3588

cve-icon Redhat

Severity : Low

Publid Date: 2021-01-04T00:00:00Z

Links: CVE-2021-3588 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses