Insufficient Validation in Bluetooth AVRCP Implementation in BlueZ
CVE-2026-75032

6.3MEDIUM

What is CVE-2026-75032?

A vulnerability in the BlueZ Bluetooth stack allows for insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP). This flaw enables a nearby malicious Bluetooth device to initiate an out-of-bounds memory read, potentially leading to a crash of the bluetoothd daemon. The exploitation of this vulnerability, particularly affecting the parse_media_element() and parse_media_folder() functions, can result in a Denial of Service (DoS) and may disclose sensitive heap memory contents. User interaction is required to pair with the malicious device for successful exploitation.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.