VYPR
Unrated severityNVD Advisory· Published Aug 18, 2022· Updated May 5, 2025

CVE-2021-26257

CVE-2021-26257

Description

Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper buffer restrictions in Intel Wireless Bluetooth and Killer Bluetooth firmware before 22.120 allow an authenticated local attacker to cause denial of service.

Vulnerability

An improper buffer restriction vulnerability exists in the firmware of certain Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products prior to version 22.120 [1]. This flaw occurs when the firmware handles specific input data without proper bounds checking, potentially leading to a buffer overflow condition. The affected products include a range of wireless adapters used in laptops and desktops. The vulnerability is exploitable only by an attacker with local access and valid authentication credentials.

Exploitation

To exploit this vulnerability, an attacker must have local access to the system and be authenticated as a user. The attacker can then send specially crafted input to the Bluetooth firmware, triggering the improper buffer restriction and causing a buffer overflow. This sequence of actions does not require elevated privileges beyond standard user access. The exact steps involve interacting with the Bluetooth subsystem via local interfaces, such as through a custom application or script that sends malformed data to the firmware.

Impact

Successful exploitation leads to a denial of service (DoS) condition. The attacker can cause the Bluetooth firmware to crash or become unresponsive, disrupting Bluetooth functionality on the affected system. This may result in system instability or require a reboot to restore normal operation. The impact is limited to availability; no data confidentiality or integrity is compromised, and no privilege escalation is achieved.

Mitigation

Intel has released firmware version 22.120 to address this vulnerability [1]. Users should update their Bluetooth firmware to version 22.120 or later through the Intel Driver & Support Assistant or the device manufacturer's update tools. No workarounds are available for systems that cannot be updated. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

References
  1. INTEL-SA-00628

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.