Integer Overflow Vulnerability in Bluetooth Host Stack by Zephyr Project
CVE-2025-12035

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 December 2025

What is CVE-2025-12035?

An integer overflow vulnerability has been identified within the Bluetooth Host stack, particularly in the bt_br_acl_recv function. This issue affects the processing of inbound Basic Rate/Enhanced Data Rate (BR/EDR) L2CAP traffic, potentially allowing attackers to exploit this flaw to disrupt normal operations or execute unauthorized commands.

Affected Version(s)

Zephyr * <= 4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12035 : Integer Overflow Vulnerability in Bluetooth Host Stack by Zephyr Project