CVE-2026-28526: BlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB Read
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LISTPLAYERAPPLICATIONSETTINGATTRIBUTES and LISTPLAYERAPPLICATIONSETTINGVALUES handlers that allows attackers to read beyond buffer boundaries. A nearby attacker with a paired Bluetooth Classic connection can send a specially crafted VENDORDEPENDENT response with an attacker-controlled count value to trigger an out-of-bounds read from the L2CAP receive buffer, potentially causing a crash on resource-constrained devices.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BlueKitchen BTstackto a version that resolves this vulnerability.Fixed in 1.8.1 - Compensating control
Disable or restrict Bluetooth Classic AVRCP Controller functionality to prevent paired attackers from sending crafted AVRCP VENDOR_DEPENDENT responses that target the L2CAP receive buffer OOB read.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28526?
CVE-2026-28526 is rated as a medium severity vulnerability due to its potential impact on user data privacy.
How do I fix CVE-2026-28526?
To fix CVE-2026-28526, update BlueKitchen BTstack to version 1.8.1 or later.
What is the impact of CVE-2026-28526?
CVE-2026-28526 can lead to information leakage via an out-of-bounds read in the AVRCP controller.
Which versions of BlueKitchen BTstack are affected by CVE-2026-28526?
BlueKitchen BTstack versions prior to 1.8.1 are affected by CVE-2026-28526.
Is CVE-2026-28526 exploitable remotely?
Yes, CVE-2026-28526 can be exploited remotely if the device is connected to an untrusted source.