Description
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade Firmware
AI Analysis

Impact

A heap overflow exists in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware. The overflow is triggered by a crafted L2CAP packet, leading to a denial of service by disrupting audio functionality. The vendor’s description does not mention any impact on confidentiality or integrity, so it is inferred that these aspects are not affected.

Affected Systems

The flaw affects BES2300 firmware versions 3.x and earlier. Devices using any of these firmware releases from Bestechnic Co., Ltd are vulnerable. No CNA product is listed, so vulnerable devices may be identified by the SoC model or firmware release name.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk, while the lack of EPSS data and absence from CISA KEV suggests the exploit is not yet widely used. The attacker must transmit a malicious L2CAP packet via Bluetooth, likely requiring proximity. No publicly available exploits have been documented, but a heap overflow could be relatively simple to trigger once the device’s Bluetooth interface is reachable.

Generated by OpenCVE AI on September 8, 2026 at 16:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BES2300 SoC firmware to a version that addresses the heap overflow, such as firmware 3.1 or later.
  • If a firmware update is not yet released, block or limit L2CAP traffic from untrusted devices by configuring the Bluetooth controller to reject packets that do not match expected sequence numbers or length.
  • Disable unnecessary Bluetooth services (for example, the A2DP profile) when not in use to reduce the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title A2DP Decoder Heap Overflow Allows Bluetooth DoS on BES2300 SoC

Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Bestechnic
Bestechnic bes2300
Vendors & Products Bestechnic
Bestechnic bes2300

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
References

Subscriptions

Bestechnic Bes2300
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T14:07:42.281Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79377

cve-icon Vulnrichment

Updated: 2026-09-08T14:07:36.575Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T14:17:28.457

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-79377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow