A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification. This leads to undefined behavior, including potential assertion failures, crashes, or memory corruption, depending on the BLE stack implementation.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zephyrproject-rtos
Zephyrproject-rtos zephyr |
|
Vendors & Products |
Zephyrproject-rtos
Zephyrproject-rtos zephyr |
Fri, 19 Sep 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification. This leads to undefined behavior, including potential assertion failures, crashes, or memory corruption, depending on the BLE stack implementation. | |
Title | Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requests | |
Weaknesses | CWE-190 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: zephyr
Published: 2025-09-19T05:21:33.363Z
Updated: 2025-09-19T11:57:01.588Z
Reserved: 2025-09-15T05:10:24.872Z
Link: CVE-2025-10456

Updated: 2025-09-19T11:56:56.866Z

Status : Awaiting Analysis
Published: 2025-09-19T06:15:34.000
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-10456

No data.