Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85218

Опубликовано: 03 сент. 2026
Источник: redhat
CVSS3: 7.1

Описание

A double stack-based buffer overflow was found in the BlueZ AVRCP controller implementation. A nearby BR/EDR peripheral can send a crafted AVRCP player-settings response that supplies an attacker-controlled attribute count, causing avrcp_list_player_attributes_rsp() and avrcp_get_current_player_value() in profiles/audio/avrcp.c to write attacker-controlled data past fixed-size stack buffers, potentially leading to a crash or code execution in the bluetoothd daemon.

Отчет

Red Hat CVSSv3 score is an estimate from CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. This vulnerability requires user interaction and does not have any impact on the subsequent system, thus the scope is unchanged.

Меры по смягчению последствий

Affected version is v5.87 and fixed in commit b21c216d580cf303681bfe9eab60a5414d8b6cc0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bluezAffected
Red Hat Enterprise Linux 6bluezNot affected
Red Hat Enterprise Linux 7bluezNot affected
Red Hat Enterprise Linux 8bluezNot affected
Red Hat Enterprise Linux 9bluezAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2528163bluez: bluez: AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value

7.1 High

CVSS3

Связанные уязвимости

ubuntu
9 дней назад

[Unknown description]

debian

Описание отсутствует

7.1 High

CVSS3