CVE-2026-28528: BlueKitchen BTstack < 1.8.1 AVRCP Browsing Target GET_FOLDER_ITEMS Handler OOB Read / Undefined Behavior
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GETFOLDERITEMS handler that fails to validate packet boundaries and attribute count data. An attacker with a paired Bluetooth Classic connection can exploit insufficient bounds checking on the attrid parameter to cause crashes and corrupt attribute bitmap state.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BlueKitchen BTstack AVRCP Browsing Target (GET_FOLDER_ITEMS handler)to a version that resolves this vulnerability.Fixed in 1.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28528?
CVE-2026-28528 is classified as a medium severity vulnerability due to its potential for triggering undefined behavior.
How do I fix CVE-2026-28528?
To fix CVE-2026-28528, users should update BlueKitchen BTstack to version 1.8.1 or later.
What impact does CVE-2026-28528 have on BlueKitchen BTstack users?
CVE-2026-28528 can allow attackers to exploit out-of-bounds reads, potentially leading to application crashes or unintended data exposure.
Which versions of BlueKitchen BTstack are affected by CVE-2026-28528?
BlueKitchen BTstack versions earlier than 1.8.1 are affected by CVE-2026-28528.
How does CVE-2026-28528 occur in BlueKitchen BTstack?
CVE-2026-28528 occurs due to the failure to validate packet boundaries and attribute count data in the AVRCP Browsing Target GET_FOLDER_ITEMS handler.