Описание
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Missing length checks have been discovered in the Qt bluetooth QLowEnergyController class. An external device can send malformed Bluetooth ATT commands to trigger read past the end of the buffer and division by zero errors which may lead to a denial of service on the host device. In the central role the user has to explicitly connect to the attacking external device before the malformed commands are processed.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | qt6 | Fix deferred | ||
| Red Hat Enterprise Linux 6 | qt | Out of support scope | ||
| Red Hat Enterprise Linux 6 | qt3 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | qt | Out of support scope | ||
| Red Hat Enterprise Linux 7 | qt3 | Out of support scope | ||
| Red Hat Enterprise Linux 8 | qt5 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | qt5 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
3.1 Low
CVSS3
Связанные уязвимости
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ...
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
3.1 Low
CVSS3