Description
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
Published: 2026-07-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An off‑by‑one error in the BlueZ SBC codec decoder allows a crafted audio payload to cause a one‑byte heap out‑of‑bounds read. The read can expose an adjacent byte of heap memory to an attacker streaming Bluetooth audio, potentially revealing sensitive information. The vulnerability is a heap out‑of‑bounds read (CWE‑125) and does not provide a code execution path.

Affected Systems

The flaw affects Red Hat Enterprise Linux 7, 8, 9 and 10 where the BlueZ SBC codec library is installed. The CNA lists these RHEL releases as affected. No other vendors are listed, and the standard Red Hat distribution packages are impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an SBC frame via a Bluetooth audio stream. Based on the EPSS score, the probability of exploitation is low in practice.

Generated by OpenCVE AI on August 4, 2026 at 15:47 UTC.

Remediation

Vendor Workaround

There is no practical mitigation short of disabling Bluetooth A2DP audio decoding entirely. The SBC codec is mandatory for A2DP and the decode path is invoked automatically on incoming Bluetooth audio streams.


OpenCVE Recommended Actions

  • Disable Bluetooth A2DP audio decoding entirely on affected systems to prevent execution of the vulnerable codec path.
  • If disabling A2DP is not feasible, consider disabling the Bluetooth service or limiting Bluetooth device pairing to trusted devices.
  • Monitor Bluetooth activity for unauthorized audio streams and apply vendor best practices for Bluetooth configuration.

Generated by OpenCVE AI on August 4, 2026 at 15:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:15:00 +0000


Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Sbc
Sbc sbc
Vendors & Products Sbc
Sbc sbc

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
Title Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-30T14:01:24.071Z

Reserved: 2026-07-21T14:03:06.762Z

Link: CVE-2026-16473

cve-icon Vulnrichment

Updated: 2026-07-22T18:31:07.858Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T11:16:50.097

Modified: 2026-07-30T14:16:47.573

Link: CVE-2026-16473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses