https://seclists.org/oss-sec/2026/q3/498: CVE quest: BlueZ AVRCP Out-of-Bounds ad (CWE-125)
Published Aug 14, 2026
·Updated
Affected Software
1 affected component
BlueZ bluetoothd<bd8989620ed6
CVE-2026-XXXX is classified as a medium-severity vulnerability due to the potential for remote exploitation.
To fix CVE-2026-XXXX, update to the latest version of BlueZ that includes the vulnerability patch.
CVE-2026-XXXX affects versions of the BlueZ Bluetooth stack prior to the security update released on August 14, 2026.
Not addressing CVE-2026-XXXX may allow remote attackers to perform out-of-bounds read operations and potentially disclose sensitive information.
CVE-2026-XXXX is an Out-of-Bounds Read vulnerability that involves improper handling of AVRCP GetFolderItems parsing in BlueZ.