PT-2026-29025 · Btstack · Btstack

·

CVE-2026-28526

·

Published

2026-03-30

·

Updated

2026-03-30

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BTstack versions prior to 1.8.1
Description The software contains an out-of-bounds read issue within the AVRCP Controller LIST PLAYER APPLICATION SETTING ATTRIBUTES and LIST PLAYER APPLICATION SETTING VALUES handlers. An attacker with a paired Bluetooth Classic connection can send a crafted VENDOR DEPENDENT response with a controlled count value to trigger a read beyond the L2CAP receive buffer boundaries, potentially causing a crash on devices with limited resources.
Recommendations Update to version 1.8.1 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28526

Affected Products

Btstack