Related Vulnerabilities: CVE-2021-3588  

A security issue has been found in BlueZ before version 5.56. The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue has been found in BlueZ before version 5.56. The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

AVG-2061 bluez 5.55-3 5.56-1 Medium Fixed

https://github.com/bluez/bluez/issues/70
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?h=5.56&id=3a40bef49305f8327635b81ac8be52a3ca063d5a