Impact
This vulnerability in BlueZ’s A2DP stack permits a stack-based buffer overflow (CWE‑121) by manipulating stream endpoints. When a malicious Bluetooth device is paired, the length of user‑supplied data is not validated before copying it into a fixed‑length buffer, enabling arbitrary code execution with root privileges. The flaw requires an attacker to first establish a Bluetooth connection and pair a device that supplies crafted data.
Affected Systems
The flaw affects BlueZ deployments that handle A2DP stream endpoints. No specific version information is listed, so all BlueZ installations that use the vulnerable code path are potentially impacted. Administrators should verify whether their systems run BlueZ and identify the installed version.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1 and no EPSS value, and it is not listed in the CISA KEV catalog. Exploitation requires proximity and a successful pairing with a malicious Bluetooth device. The probable attack vector is Bluetooth communication, specifically a paired A2DP stream, allowing a nearby attacker to gain root privileges on the target. Given the absence of EPSS data and KEV listing, the likelihood of active exploitation is uncertain, but the potential impact warrants proactive mitigation.
OpenCVE Enrichment