CVE-2026-12236Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. The per-entry stride rsp->len is taken directly from the peer's PDU, and the parse loop both tests its exit condition (length >= rsp->len) and advances (length -= rsp->len, pdu += rsp->len) using that value. The minimum value of rsp->len was never validated before the loop. A malicious or malfunctioning peer can reply with rsp->len = 0. Because length is unsigned and never decreases, the loop condition stays true forever and the read pointer never advances; as long as the body is at least a few bytes with a non-zero handle and a matching descriptor UUID, the host repeatedly re-parses the same bytes and invokes the discovery callback, never terminating. This hangs the Bluetooth host processing thread (CWE-835, loop with unreachable exit condition). The condition is reachable by any connected peer once the local device initiates standard-descriptor-value discovery; GATT discovery does not require bonding or encryption, so an unauthenticated adjacent attacker that the device connects to can trigger it. The impact is denial of service of the Bluetooth subsystem (and likely a watchdog reset on constrained targets); there is no memory disclosure or corruption. The fix adds a rsp->len < sizeof(struct bt_att_data) check before the loop, rejecting under-length responses so the stride is always non-zero and the loop terminates. The sibling parsers parse_include() and parse_characteristic() already validated rsp->len and are unaffected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-13); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-13: 2Mentions · 2026-08-14: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-14: 108-1308-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-132
Disclosure1General1
2026-08-141
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12236 Bluetooth Host Denial of Service via GATT Client Parsing Flaw https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12236

    Post summary

    The text announces the CVE-2026-12236, describing it as a Bluetooth host denial‑of‑service vulnerability caused by a GATT client parsing flaw, with a link to vulnerability details but no PoC, exploit code, or patch information.

    00000104
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12236 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT ser… https://www.cve.org/CVERecord?id=CVE-2026-12236 ----- Traducción: CVE-2026-12236 La … https://infoflow.cloud`

    Post summary

    The tweet simply announces CVE-2026-12236 with a brief description of the impacted function and provides a link to the CVE record, containing no evidence of exploitation or mitigation.

    0000023
    97 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-12236 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT ser… https://www.cve.org/CVERecord?id=CVE-2026-12236

    Post summary

    The text offers a brief technical note on a Bluetooth GATT client vulnerability and links to the CVE record, but lacks any proof of exploitation or mitigation details.

    00000993
    57.9K followersView on X

Explore more