Impact
A stack-based buffer overflow exists in the BlueZ Bluetooth protocol stack’s name2utf8 function. When an attacker sends a malformed Extended Inquiry Response packet during a device discovery, the buffer overflow can crash the bluetoothd daemon, disrupting the Bluetooth service. The same overflow may also be exploitable for arbitrary code execution, depending on the system configuration and the attacker’s privileges.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6, 7, 8, 9 and 10, where the BlueZ stack is bundled with the operating system. Any installation of these platforms that has the Bluetooth daemon running is potentially exposed.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. EPSS data is unavailable, so the current probability of exploitation is unknown, but the flaw is locally reachable to any device within Bluetooth radio range. The vulnerability is not listed in the CISA KEV catalog. Attackers would need proximity to the target device and the ability to send a crafted EIR packet; from those constraints the threat is significant for exposed or mobile devices that use Bluetooth.
OpenCVE Enrichment