CVE-2016-9797 PUBLISHED

In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

EPSS 0.48% · 64.8th percentile

Risk Scores

EPSS Score
0.48%
64.8th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSbluez5.53-0ubuntu3.2, 5.53-0ubuntu3.1, 0
Ubuntu:25.10bluez5.83-1~exp1ubuntu0.1, 5.83-1~exp1, 5.82-1ubuntu1
Ubuntu:Pro:16.04:LTSbluez0, 5.35-0ubuntu2, 5.36-0ubuntu1
Ubuntu:22.04:LTSbluez5.64-0ubuntu1.1, 5.64-0ubuntu1.3, 5.64-0ubuntu1.4
Ubuntu:24.04:LTSbluez5.68-0ubuntu1, 5.70-0ubuntu1, 5.70-0ubuntu2
Ubuntu:Pro:18.04:LTSbluez0, 5.48-0ubuntu3.9+esm1, 5.48-0ubuntu3.9

Timeline

References

Open in Interactive Console →