Impact
An off‑by‑one error in the BlueZ SBC codec decoder allows a crafted audio payload to cause a one‑byte heap out‑of‑bounds read. The read can expose an adjacent byte of heap memory to an attacker streaming Bluetooth audio, potentially revealing sensitive information. The vulnerability is a heap out‑of‑bounds read (CWE‑125) and does not provide a code execution path.
Affected Systems
The flaw affects Red Hat Enterprise Linux 7, 8, 9 and 10 where the BlueZ SBC codec library is installed. The CNA lists these RHEL releases as affected. No other vendors are listed, and the standard Red Hat distribution packages are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an SBC frame via a Bluetooth audio stream. Based on the EPSS score, the probability of exploitation is low in practice.
OpenCVE Enrichment