GHSA-2xmm-4jcc-wgxqMediumCVSS 4.3
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-16473
- https://access.redhat.com/security/cve/CVE-2026-16473
- https://bugzilla.redhat.com/show_bug.cgi?id=2503650
- https://git.kernel.org/pub/scm/bluetooth/sbc.git
- https://lore.kernel.org/linux-bluetooth/[email protected]
- https://github.com/advisories/GHSA-2xmm-4jcc-wgxq