Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
CVE-2022-26528

6.5MEDIUM

Key Information:

Vendor

Realtek

Vendor
CVE Published:
30 August 2022

What is CVE-2022-26528?

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

Affected Version(s)

Linux/Android Bluetooth Mesh SDK <= 4.17-4.17-20220127

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.