Input validation error in Qualcomm products - #VU56328
Published: September 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the Bluetooth Classic implementation allows an LMP length overflow over 2-DH1, resulting in a Deadlock outcome. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
CSR8510
DVK-BT900-SA
Remediation
CSR8510 - update to 9.1.12.14