Division-by-Zero Vulnerability in BlueALSA's LC3plus Decoder
CVE-2026-101887

2.1LOW

Key Information:

Vendor

Arkq

Vendor
CVE Published:
1 October 2026

What is CVE-2026-101887?

The BlueALSA software experiences a critical division-by-zero vulnerability within the LC3plus sink decoder component. This flaw allows a Bluetooth-adjacent attacker to exploit the system by sending a maliciously crafted RTP media header, specifically by manipulating the frame count field to zero. When an A2DP source connection is established with a victim using bluealsad, this exploit can trigger a SIGFPE signal in the decoding thread, resulting in a denial of service. The issue particularly affects systems compiled with LC3plus support, rendering them susceptible to crashes as a result of this network-based attack vector.

Affected Version(s)

bluez-alsa 0 < 1a84465dd860d1be9dcf62339c6273e9e0632dd2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
VulnCheck
.