Description
BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A bonded Bluetooth peer can send an overly large AVDTP DISCOVER response, and because BTstack does not validate the endpoint count against the fixed-size table, the library writes beyond the bounds of its arrays. The out-of-bounds write corrupts adjacent static objects, causing the process to crash or the event delivery to be severed. This leads to a denial‑of‑service condition in applications using BTstack’s A2DP functionality.

Affected Systems

All installations of BlueKitchen BTstack version 1.8.2 or earlier, including any embedded systems or devices that use that release for Bluetooth A2DP connections. The vulnerability is tied specifically to the A2DP stream endpoint discovery code paths in that version.

Risk and Exploitability

The CVSS score of 7 indicates a high potential impact when exploited. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits at the time of this analysis. A likely attack vector requires the attacker to be a bonded peer, implying a physical proximity or prior authorization, but once bonded, the endpoint count can be leveraged to trigger the overflow.

Generated by OpenCVE AI on September 17, 2026 at 21:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade BTstack to a version that includes the endpoint count validation fix (see the commit linked in the advisories)
  • If an upgrade is not immediately possible, restrict the set of bonded peers or disable the A2DP/AVDTP discovery feature to prevent the vulnerable path from executing
  • Monitor system logs for unexpected crashes or memory corruption events that could indicate exploitation attempts

Generated by OpenCVE AI on September 17, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Bluekitchen
Bluekitchen btstack
Vendors & Products Bluekitchen
Bluekitchen btstack

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.
Title BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
Weaknesses CWE-1284
CWE-787
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bluekitchen Btstack
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:19:21.674Z

Reserved: 2026-09-17T14:46:03.640Z

Link: CVE-2026-93015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:18:35.847

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-93015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-787

    Out-of-bounds Write