Description
A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted frame.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a buffer overflow in the SBC_DecodeFrames() function of the Bestechnic BES2300 Bluetooth Audio SoC firmware. A crafted audio frame overflows an internal buffer, causing the decoder to crash or reset. Since the decoder is essential for audio playback, the result is a denial of service that disrupts audio services and may impair system reliability. The flaw is a classic unchecked buffer write represented by the CWE identifier CWE-617.

Affected Systems

Devices running the BES2300 Bluetooth Audio SoC firmware v3.x and earlier are affected. Firmware version 5.0 and later incorporates the fix, rendering those versions immune.

Risk and Exploitability

The defect can be triggered by sending a malformed audio frame over the Bluetooth interface, which is the typical delivery mechanism for audio data. The CVSS score of 6.5 reflects moderate severity, while the EPSS score of <1% indicates a low likelihood of exploitation. The flaw is not listed in CISA KEV, suggesting it has not been widely exploited in the wild. Exploitation would require proximity to the device to deliver the crafted frame.

Generated by OpenCVE AI on September 21, 2026 at 07:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the firmware update to version 5.0 or newer to incorporate the overflow fix.
  • If a firmware update is not available immediately, disable or block the reception of Bluetooth audio frames to stop crafted frames from reaching the decoder.
  • Continuously monitor system logs and Bluetooth traffic for abnormal parsing errors or repeated frame activity, and block traffic from untrusted or unknown devices.

Generated by OpenCVE AI on September 21, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Bluetooth Audio Decoder Causes DoS

Mon, 21 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Bluetooth Audio Decoder Causes Denial of Service in Bestechnic BES2300 SoC
Weaknesses CWE-120
CWE-787

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Bluetooth Audio Decoder Causes Denial of Service in Bestechnic BES2300 SoC
Weaknesses CWE-120
CWE-787

Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Bestechnic
Bestechnic bes2300
Vendors & Products Bestechnic
Bestechnic bes2300

Tue, 08 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted frame.
References

Subscriptions

Bestechnic Bes2300
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T13:46:08.264Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79379

cve-icon Vulnrichment

Updated: 2026-09-14T13:45:50.720Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T14:17:28.683

Modified: 2026-09-14T14:17:10.130

Link: CVE-2026-79379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:45:11Z

Weaknesses