Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wfr-vqp9-gqc3

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

EPSS

Процентиль: 10%
0.00196
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.3
ubuntu
9 дней назад

(A flaw was found in BlueZ. Insufficient validation of packet length fi ...)

CVSS3: 6.3
redhat
11 дней назад

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

CVSS3: 6.3
nvd
9 дней назад

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

msrc
6 дней назад

Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

CVSS3: 6.3
debian
9 дней назад

A flaw was found in BlueZ. Insufficient validation of packet length fi ...

EPSS

Процентиль: 10%
0.00196
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-125