Impact
BlueZ’s sdp-xml.c contains a type‑confusion flaw that is triggered via the RegisterProfile(ServiceRecord) API. A crafted nested ServiceRecord corrupts the SDP XML parser’s stack, causing scalar union data to be interpreted as a sequence pointer. The resulting memory corruption crashes the bluetoothd daemon, leading to a local denial of service that can affect any user able to register a profile on the machine. The vulnerability is classified as CWE‑843.
Affected Systems
Systems running Red Hat Enterprise Linux 6, 7, 8, 9 or 10 with BlueZ 5.86 are affected. Any host that exposes the Bluetooth daemon on a local interface and allows users to register profiles can be impacted.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is local: an unprivileged user who can invoke RegisterProfile can trigger the daemon crash. Because the impact is limited to service availability and does not provide code execution or elevation, the overall risk is moderate but remains significant for uptime and stability.
OpenCVE Enrichment