Home

Description

A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification. This leads to undefined behavior, including potential assertion failures, crashes, or memory corruption, depending on the BLE stack implementation.

PUBLISHED Reserved 2025-09-15 | Published 2025-09-19 | Updated 2025-09-19 | Assigner zephyr




HIGH: 7.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Problem types

Integer Overflow or Wraparound

Product status

Default status
unaffected

* (git)
affected

References

github.com/...zephyr/security/advisories/GHSA-hcc8-3qr7-c9m8

cve.org (CVE-2025-10456)

nvd.nist.gov (CVE-2025-10456)

Download JSON