Medium severity5.9NVD Advisory· Published Jul 10, 2023· Updated Jun 17, 2026
CVE-2023-1902
CVE-2023-1902
Description
The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*range: <=3.3.0
- (no CPE)
- (no CPE)range: *
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.