PT-2026-29027 · Bluekitchen · Btstack
Vulncheck
·
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2026-28528
CVSS v3.1
4.6
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
BlueKitchen BTstack versions prior to 1.8.1
Description
The software contains a flaw where it does not properly check the limits of data packets and attribute counts. An attacker who has paired a Bluetooth Classic connection can take advantage of this insufficient boundary check on the
attr id parameter. This can lead to crashes and corruption of the attribute bitmap state. The vulnerability resides in the AVRCP Browsing Target GET FOLDER ITEMS handler.Recommendations
Update to version 1.8.1 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Btstack