Description
BlueKitchen BTstack contains an out-of-bounds read vulnerability in the AVRCP Browsing Target GET_FOLDER_ITEMS handler that fails to validate packet boundaries and attribute count data. An attacker with a paired Bluetooth Classic connection can exploit insufficient bounds checking on the attr_id parameter to cause crashes and corrupt attribute bitmap state.
Problem types
CWE-758 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
Product status
Any version before 1.8.1
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
VulnCheck
References
github.com/bluekitchen/btstack/releases/tag/v1.8.1
www.vulncheck.com/…ems-handler-oob-read-undefined-behavior
