CVE-2026-93015: BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BlueKitchen BTstack A2DP SEP (A2DP stream endpoint discovery)to a version that resolves this vulnerability.Fixed in 1.8.2
Event History
Frequently Asked Questions
Who can exploit this issue?
A bonded Bluetooth peer can exploit it by sending a crafted AVDTP DISCOVER response reporting more A2DP stream endpoints than the fixed endpoint table can hold.
What conditions are required for exploitation?
The attacker needs to be a bonded peer and must be able to provide an AVDTP DISCOVER response during A2DP stream endpoint discovery. No user interaction is required.
What is the operational impact of a successful exploit?
The out-of-bounds writes can corrupt adjacent static objects, crash the process, or sever event delivery. The provided data identifies availability impact as high and integrity impact as low.
Which versions are affected?
BlueKitchen BTstack through version 1.8.2 is affected.