Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16473

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 4.3

Описание

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

Меры по смягчению последствий

There is no practical mitigation short of disabling Bluetooth A2DP audio decoding entirely. The SBC codec is mandatory for A2DP and the decode path is invoked automatically on incoming Bluetooth audio streams.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10sbcFix deferred
Red Hat Enterprise Linux 7sbcFix deferred
Red Hat Enterprise Linux 8sbcFix deferred
Red Hat Enterprise Linux 9sbcFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2503650sbc: sbc: heap out-of-bounds read via crafted SBC audio frame

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
26 дней назад

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

CVSS3: 4.3
nvd
26 дней назад

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

CVSS3: 4.3
debian
26 дней назад

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...

CVSS3: 4.3
github
26 дней назад

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

4.3 Medium

CVSS3