Impact
Buffer over-read occurs in the Bluetooth controller when processing a channel map that contains fewer used channels than expected, while adaptive frequency hopping is enabled. The improper bounds checking can lead to a transient denial of service, causing the controller to hang or reset. This flaw falls under CWE-126, which describes over-reading of a buffer.
Affected Systems
Qualcomm Snapdragon devices are affected. Specific model or firmware version information is not provided in the advisory, so any Snapdragon processor running the current Bluetooth stack may be vulnerable. The issue is tied to the controller’s handling of channel map messages.
Risk and Exploitability
The CVSS score of 7.4 indicates moderate to high severity, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote through Bluetooth communication, where an attacker could send a crafted channel map packet to trigger the over-read. Because the vulnerability requires interaction with the Bluetooth stack, it is less attractive to attackers, but devices with runtime access or adjacent devices could be affected.
OpenCVE Enrichment