Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)

Дата публикации: 14-08-2026 20:28:45

Posted by Elman Shahbazov on Aug 14Hello,
I would like to request a CVE ID for an Out-of-Bounds Read vulnerability
(CWE-125) that was recently fixed in the official BlueZ Bluetooth stack.
Vulnerability Type: CWE-125 (Out-of-bounds Read)
Component: profiles/audio/avrcp.c (AVRCP GetFolderItems parsing)
Impact: A remote Bluetooth device acting as an AVRCP controller can send
a specially crafted response with an inflated name length field but a short
packet size, causing...


Основное содержимое страницы с новостью.

oss-sec logo oss-sec mailing list archives
From: Elman Shahbazov <shahbazovelman97 () gmail com>
Date: Fri, 14 Aug 2026 21:27:43 +0400

Hello,

I would like to request a CVE ID for an Out-of-Bounds Read vulnerability
(CWE-125) that was recently fixed in the official BlueZ Bluetooth stack.

Vulnerability Type: CWE-125 (Out-of-bounds Read)
Component: profiles/audio/avrcp.c (AVRCP GetFolderItems parsing)
Impact: A remote Bluetooth device acting as an AVRCP controller can send
  a specially crafted response with an inflated name length field but a short
  packet size, causing bluetoothd to read past the allocated packet buffer
  (Denial of Service / Information Disclosure).

The vulnerability was discovered by me, and the patch has been officially
accepted and applied to the BlueZ master branch by the maintainers
(Red Hat / Intel).

Fixed Commit:
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=bd8989620ed6

Discoverer: Elman Shahbazov (shahbazovelman97 () gmail com)

Thank you,
Elman Shahbazov


Current thread:

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Re: CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)013.1114-08-2026
2CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse08.7515-08-2026
3Переполнение буфера в iwd, эксплуатируемое через Wi-Fi013.1803-08-2026
4CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse09.6915-08-2026
5Атакована недоисправленная уязвимость в Windows-2609-07-2026
6croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)01314-08-2026
7croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)01314-08-2026
8archivers/zip - 3.0_608.4815-08-2026
9New U-Boot flaws could enable stealthy firmware attacks-2710-07-2026
10Info-ZIP test option (-T) command injection011.4814-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.12. Источник: seclists.org.