Red Hat Bugzilla – Bug 1401543
CVE-2016-9803 bluez: out-of-bounds read in le_meta_ev_dump()
Last modified: 2016-12-05 09:30:18 EST
An out-of-bounds read was found in the le_meta_ev_dump() function in tools/parser/hci.c source file of bluez. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed. Original report: https://www.spinics.net/lists/linux-bluetooth/msg68892.html