Description
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Problem types
Product status
Any version before 5.15.19
6.0.0 (custom) before 6.5.9
6.6.0 (custom) before 6.8.2
References
codereview.qt-project.org/q/QLowEnergyController
www.qt.io/...security-advisory-qlowenergycontroller-on-linux