Impact
The Zephyr Bluetooth Classic L2CAP receive handler processes data PDUs without verifying that a channel is fully connected. An attacker can send a data packet to a channel still in the CONNECTING or CONFIGURATION state, causing the packet to be delivered to upper‑layer protocol handlers on a half‑open channel, potentially leading to a denial of service or a dangling‑pointer condition when stale channel state is reused.
Affected Systems
The flaw affects Zephyr RTOS (Zephyr project) devices that use the Bluetooth Classic L2CAP receive path. The affected code is in subsys/bluetooth/host/classic/l2cap_br.c. Exact Zephyr versions are not specified in the advisory, so any build that includes this source file is potentially vulnerable until the patch is applied.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate. No EPSS score is available and it is not listed in KEV. The exploit requires a remote peer to be within radio range and to send a crafted L2CAP data PDU addressed to the target channel identifier. Once the packet is received it bypasses the CONNECTED state check, triggering channel processing on a not‑yet‑established or reused channel, which can cause channel teardown, denial of service or memory corruption. Because the window exists when the channel is in CONNECTING/CONFIGURATION, the likelihood of exploitation in the wild is low but still possible for systems exposed to Bluetooth traffic.
OpenCVE Enrichment