ORSHIN Attack Defense Framework

Stack overflow in L2CAP

Description

Stack overflow in L2CAP

Risk Assesment: 8.0

CWE

787

CVE

1000251

Attack Surfaces

Kernel or Operating System (MITRE EMB3D PID-23)

Kernel or Operating System (MITRE EMB3D PID-23)

Controller Implementation (MITRE EMB3D PID-11)

BlueZ

Attack Vectors

RCE (MITRE EMB3D TID-310)

Defenses

Check L2CAP config option output buffer length, Validate output buffer length for L2CAP config requests and responses