CVE-2026-75032: Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

Published Aug 17, 2026
·
Updated

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parsemediaelement() and parsemediafolder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.

Affected Software

1 affected component
BlueZ BlueZ

Event History

Aug 17, 2026
Data Sourced
via Red Hat·04:26 PM
DescriptionSeverityAffected Software
Aug 18, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems running BlueZ are exposed when a malicious Bluetooth device is within radio range and can be paired through user interaction. The reported impact is a bluetoothd daemon crash, with potential exposure of sensitive heap-memory contents.

2

What does an attacker need to exploit the vulnerability?

An attacker needs to be within Bluetooth range, operate a malicious Bluetooth device, and induce the user to pair with it. The vulnerable parsing occurs when handling AVRCP GetFolderItems responses.

3

How can I determine whether my deployment is affected?

The provided information does not identify affected or fixed BlueZ versions, nor does it state whether the vulnerable AVRCP behavior is enabled in a default configuration. Confirm exposure by determining whether the deployed BlueZ instance processes AVRCP GetFolderItems responses from paired Bluetooth devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203