Impact
A flaw in BlueZ’s AVRCP implementation allows an out‑of‑bounds read during GetFolderItems response parsing. The error can crash the bluetoothd daemon, causing a denial of service, and, because the read may expose heap contents, there is a possibility of leaking sensitive data. The vulnerability is triggered by insufficient validation of packet length fields in the parse_media_element() and parse_media_folder() functions.
Affected Systems
The issue affects Red Hat Enterprise Linux releases 10 through 9 where BlueZ is present and the AVRCP profile is enabled. Any system running these OS versions and accepting Bluetooth connections is potentially impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low or uncertain exploitation rates. However, exploitation requires a Bluetooth device to be within range and a user to pair with it, so the attack vector is local but requires user interaction. Systems that keep the AVRCP profile or allow generic pairing are at higher risk of DoS or accidental data leakage.
OpenCVE Enrichment