Impact
Zephyr RTOS’s Bluetooth Classic Hands‑Free Profile Hands‑Free role parser contains an out‑of‑bounds write in cind_handle_values() when processing the AT+CIND=? response from an Attendant Gateway. During Service Level Connection setup the HF sends the AT+CIND=? command and parses the AG's +CIND: reply in cind_handle(); this assigns a per‑entry counter index and calls cind_handle_values() for each list element. Inside cind_handle_values() the code writes hf->ind_table[index] = i without checking that index is within the 20‑element ind_table[] array of struct bt_hfp_hf. Because the parser places no limit on the number of +CIND: list entries, a malicious Attendant Gateway can send a response with more than twenty indicators, causing index to grow arbitrarily large and overwrite adjacent fields such as feature masks, SDP/version state, the calls[] array, work/atomic bookkeeping, and potentially beyond the static connection pool. This memory corruption results in at least a denial of service of the Bluetooth host and can be triggered by a single malformed AT response with no user interaction. The consumer ag_indicator_handle_values() already performed the equivalent bounds check; the commit cf7693a8261ae363c9cf46cfd51005486637173e adds the same index ≥ ARRAY_SIZE(hf->ind_table) guard to close the gap. The flaw is present in builds with CONFIG_BT_HFP_HF enabled, introduced with the original HFP HF CIND parser (~v1.7) and exists through v4.4.0.
Affected Systems
Zephyr Project’s Zephyr RTOS, specifically the Bluetooth Classic Hands‑Free Profile implementation when CONFIG_BT_HFP_HF is enabled. The flaw was introduced in the initial HFP HF CIND parser around version 1.7 and exists in releases up to and including v4.4.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity flaw, and the vulnerability is not listed in CISA’s KEV. The EPSS score of <1% shows a very low current likelihood of exploitation, but because the flaw can be triggered remotely with a single malformed AT message during Service Level Connection setup, any device running the vulnerable Zephyr build and exposing the Hands‑Free role remains at risk. The attack requires no user action and can occur over an open Bluetooth connection, underscoring the need to apply the patch promptly.
OpenCVE Enrichment