The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the target device with LMP_features_res packets.
https://www.actions-semi.com/index.php?id=3581&siteId=4
https://launchstudio.bluetooth.com/ListingDetails/76427
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf