zephyrproject-rtos
CVE Severity Distribution (All Time)
Timeline Overview
Products
View allRecent CVEs
View allNo proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata sectio…
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
BT: Classic: SDP OOB access in get_att_search_list
BT:Classic: Multiple missing buf length checks
BT: Unchecked user input in bap_broadcast_assistant
BT: Missing length checks of net_buf in rfcomm_handle_data