7.6
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Description
Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabling precise memory corruption.
Basic Information
ID
CVE-2025-7403
Source
zephyr
Published
Sep 19, 2025 at 05:19
Affected Product
Vendor
zephyrproject-rtos
Product
Zephyr
Version
*
Affected Versions
zephyrproject-rtos Zephyr *