CVE-2026-101887: BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS
BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dplc3plusdecthread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments running bluealsad as an A2DP sink are exposed only when built with LC3plus support enabled and an LC3plus session can be negotiated with an A2DP source.
What does an attacker need to trigger the crash?
The attacker needs Bluetooth-adjacent access, the ability to establish an A2DP source connection with the victim, and an LC3plus session. They then send a non-fragmented LC3plus RTP media header whose frame-count field is zero.
What is the operational impact of successful exploitation?
The crafted header causes a SIGFPE in the LC3plus decoding thread, crashing the daemon and producing a denial of service. The provided information does not indicate confidentiality impact or code execution.