Integer Overflow Vulnerability in Bluetooth Host Stack by Zephyr Project
CVE-2025-12035
6.5MEDIUM
What is CVE-2025-12035?
An integer overflow vulnerability has been identified within the Bluetooth Host stack, particularly in the bt_br_acl_recv function. This issue affects the processing of inbound Basic Rate/Enhanced Data Rate (BR/EDR) L2CAP traffic, potentially allowing attackers to exploit this flaw to disrupt normal operations or execute unauthorized commands.
Affected Version(s)
Zephyr * <= 4.2
