Description
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.
Published: 2026-08-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in BlueZ’s AVRCP implementation allows an out‑of‑bounds read during GetFolderItems response parsing. The error can crash the bluetoothd daemon, causing a denial of service, and, because the read may expose heap contents, there is a possibility of leaking sensitive data. The vulnerability is triggered by insufficient validation of packet length fields in the parse_media_element() and parse_media_folder() functions.

Affected Systems

The issue affects Red Hat Enterprise Linux releases 10 through 9 where BlueZ is present and the AVRCP profile is enabled. Any system running these OS versions and accepting Bluetooth connections is potentially impacted.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low or uncertain exploitation rates. However, exploitation requires a Bluetooth device to be within range and a user to pair with it, so the attack vector is local but requires user interaction. Systems that keep the AVRCP profile or allow generic pairing are at higher risk of DoS or accidental data leakage.

Generated by OpenCVE AI on August 18, 2026 at 17:00 UTC.

Remediation

Vendor Workaround

Disable the AVRCP Bluetooth profile if it is not needed, or restrict Bluetooth pairing to trusted devices only. On systems where Bluetooth is not required, disable the Bluetooth subsystem entirely.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Enterprise Linux updates that contain the BlueZ fix once they are released.
  • If the AVRCP profile is needed, disable it or restrict Bluetooth pairing to trusted devices only.
  • On machines that do not require any Bluetooth functionality, disable the Bluetooth subsystem entirely.

Generated by OpenCVE AI on August 18, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.
Title Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-19T14:29:16.198Z

Reserved: 2026-08-17T15:16:35.130Z

Link: CVE-2026-75032

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T15:17:12.473

Modified: 2026-08-20T13:08:53.900

Link: CVE-2026-75032

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-17T00:00:00Z

Links: CVE-2026-75032 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:48Z

Weaknesses