The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and restart (crash) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cyw920735q60evb-01_firmware | Cypress | - (including) | - (including) |
Bluez-firmware | Ubuntu | kinetic | * |
Bluez-firmware | Ubuntu | lunar | * |
Bluez-firmware | Ubuntu | mantic | * |
Bluez-firmware | Ubuntu | trusty | * |
Bluez-firmware | Ubuntu | xenial | * |