PT-2026-29025 · Btstack · Btstack

·

CVE-2026-28526

·

Publicado

2026-03-30

·

Atualizado

2026-03-30

CVSS v3.1

5.7

Média

VetorAV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BTstack versions prior to 1.8.1
Description The software contains an out-of-bounds read issue within the AVRCP Controller LIST PLAYER APPLICATION SETTING ATTRIBUTES and LIST PLAYER APPLICATION SETTING VALUES handlers. An attacker with a paired Bluetooth Classic connection can send a crafted VENDOR DEPENDENT response with a controlled count value to trigger a read beyond the L2CAP receive buffer boundaries, potentially causing a crash on devices with limited resources.
Recommendations Update to version 1.8.1 or later.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28526

Produtos afetados

Btstack