Impact
A stack‑buffer overflow occurs in the Bluetooth Mesh On‑Demand Private Proxy solicitation handler when a received Solicitation PDU is copied into a fixed 17‑byte buffer without validating the source length. The overflow happens before decryption or authentication, so no key material is needed. An attacker can craft a non‑connectable BLE advertisement containing a malicious Solicitation PDU and arbitrary trailing advertising data, causing the device to overwrite the stack. The overwrite is plausibly exploitable for remote code execution and, at minimum, provides a reliable remote denial‑of‑service.
Affected Systems
The vulnerability affects devices running the Zephyr project’s Bluetooth Mesh stack with CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled. Firmware versions that have not applied the patch from commit 4416ad13677259d180f35ce44338578694e48184 (or earlier versions that contain the same code) are vulnerable; any device capable of receiving raw BLE advertising from an attacker in radio range is impacted. No specific product or version range is listed beyond the presence of the configuration flag.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and although the EPSS value is not available, the attack can be carried out by any nearby device without additional credentials. The vulnerability is not listed in the CISA KEV catalog. The absence of input validation and the use of an unsecured buffer make exploitation straightforward under normal operational conditions, making the risk significant. It is therefore critical to apply the official patch or upgrade to a fixed version as soon as possible.
OpenCVE Enrichment