天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-19570 Zephyr 蓝牙 LE Audio 广播接收器缓冲区溢出漏洞

影响攻击者可远程触发缓冲区溢出,可能导致内存破坏或代码执行

AI 研判

Zephyr 蓝牙协议栈的 LE Audio Broadcast Sink 在处理接收到的 Basic Audio Announcement (BASE) 时,将子组元数据复制到静态参数结构 mod_src_param 中,未做边界检查。攻击者可通过周期广播发送特制 BASE 数据触发越界写入。

影响范围

Zephyr

受影响组件为 Zephyr 的 subsys/bluetooth/audio/bap_broadcast_sink.c,具体受影响版本范围暂无公开信息。

漏洞详情

漏洞类型为缓冲区溢出(越界写)。base_subgroup_meta_cb() 使用 mod_src_param.subgroups[mod_src_param.num_subgroups] 作为目标元素,未校验是否超过 ARRAY_SIZE(由 CONFIG_BT_BAP_BASS_MAX_SUBGROUPS 决定,默认 1),并用 memcpy() 按空中原始长度复制元数据到由 CONFIG_BT_AUDIO_CODEC_CFG_MAX_METADATA_SIZE(默认 4)限定的数组。BASE 校验器仅检查结构一致性,允许约 24 个子组和约 240 字节的元数据 LTV,导致溢出。

利用条件与风险

利用前提是目标设备启用 LE Audio Broadcast Sink 并处于周期广播接收状态,攻击者需在蓝牙射频范围内发送恶意广播。实战中可造成内存破坏,CVSS 8.8 属高危。

修复建议

官方修复方案暂无公开信息,建议关注 Zephyr 官方安全公告并升级至修复版本;临时缓解可限制广播接收或调整相关配置项,但需评估有效性。

原始情报

The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap_broadcast_sink.c copies subgroup metadata from a received Basic Audio Announcement (BASE) into the static Broadcast Audio Scan Service parameter structure mod_src_param without any bounds check. In base_subgroup_meta_cb() the destination element was selected as mod_src_param.subgroups[mod_src_param.num_subgroups] with no test against ARRAY_SIZE(mod_src_param.subgroups) (sized by CONFIG_BT_BAP_BASS_MAX_SUBGROUPS, default 1), and the metadata was copied with memcpy() using the raw on-air length returned by bt_bap_base_get_subgroup_codec_meta() into a metadata array sized by CONFIG_BT_AUDIO_CODEC_CFG_MAX_METADATA_SIZE (default 4). The BASE validator bt_bap_base_get_base_from_ad() only checks structural consistency and permits up to ~24 subgroups and metadata LTVs of ~240 octets.

The defect is reached from the periodic advertising receive callback: pa_recv() → bt_data_parse() → pa_decode_base() → update_recv_state_base() → bt_bap_base_foreach_subgroup() → base_subgroup_meta_cb(). Every broadcast sink registers a scan-delegator receive state at creation (bt_bap_broadcast_sink_create() calls broadcast_sink_add_src()), and CONFIG_BT_BAP_BROADCAST_SINK depends on CONFIG_BT_BAP_SCAN_DELEGATOR, so the path is active in every broadcast-sink build once the device is periodic-advertising-synced. An attacker in radio range who operates a broadcast source the device syncs to — or who impersonates the advertiser address and SID of one already in use, periodic advertising data being unauthenticated — can change the BASE at will; each new BASE is re-parsed.

A crafted BASE therefore writes attacker-chosen bytes past the end of a fixed static object in .bss: up to roughly 236 bytes for an oversized metadata LTV, plus whole struct bt_bap_bass_subgroup records for each subgroup beyond CONFIG_BT_BAP_BASS_MAX_SUBGROUPS. This is memory corruption of adjacent Bluetooth-audio state reachable with no pairing, bonding or GATT connection, with a potential for remote code execution in the Bluetooth RX thread; in addition, the unvalidated metadata_len is forwarded to bt_bap_scan_delegator_mod_src(), which neither clamps it nor rejects it, leading to a further copy into the receive state and to out-of-bounds memory being disclosed in the BASS receive-state notification sent to a connected Broadcast Assistant.

The fix rejects a BASE carrying more subgroups than the receive state can hold (discarding the update entirely) and omits metadata that does not fit rather than copying it, and additionally honours the previously-ignored error return of the subgroup decode pass.