The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
{ "urgency": "low" }