Type Confusion in BlueZ Bluetooth Daemon Affects SDP XML Parser
CVE-2026-80185

5.7MEDIUM

What is CVE-2026-80185?

A type confusion vulnerability has been identified in the BlueZ Bluetooth daemon, specifically in the handling of ServiceRecord registration within the SDP XML parser. This flaw allows for a crafted nested ServiceRecord to disrupt the stack of the SDP XML parser, causing it to misinterpret scalar union data as a sequence pointer. As a result, a local attacker could potentially exploit this weakness to crash the bluetoothd service, leading to a denial of service situation.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.