Impact
A bonded Bluetooth peer can send an overly large AVDTP DISCOVER response, and because BTstack does not validate the endpoint count against the fixed-size table, the library writes beyond the bounds of its arrays. The out-of-bounds write corrupts adjacent static objects, causing the process to crash or the event delivery to be severed. This leads to a denial‑of‑service condition in applications using BTstack’s A2DP functionality.
Affected Systems
All installations of BlueKitchen BTstack version 1.8.2 or earlier, including any embedded systems or devices that use that release for Bluetooth A2DP connections. The vulnerability is tied specifically to the A2DP stream endpoint discovery code paths in that version.
Risk and Exploitability
The CVSS score of 7 indicates a high potential impact when exploited. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits at the time of this analysis. A likely attack vector requires the attacker to be a bonded peer, implying a physical proximity or prior authorization, but once bonded, the endpoint count can be leveraged to trigger the overflow.
OpenCVE Enrichment