PT-2026-29027 · Bluekitchen Gmbh · Btstack

Vulncheck

·

Published

2026-03-30

·

Updated

2026-03-30

·

CVE-2026-28528

CVSS v3.1

4.6

Medium

AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET FOLDER ITEMS handler that fails to validate packet boundaries and attribute count data. An attacker with a paired Bluetooth Classic connection can exploit insufficient bounds checking on the attr id parameter to cause crashes and corrupt attribute bitmap state.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-28528

Affected Products

Btstack