A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bluez-deprecatedUpgrade bluez-libs-develUpgrade bluez-hid2hciUpgrade bluez-obexdUpgrade bluez-hid2hci-debuginfoUpgrade bluez-meshUpgrade bluez-mesh-debuginfoUpgrade bluez-cups-debuginfoUpgrade bluezUpgrade bluez-libs-debuginfoUpgrade bluez-obexd-debuginfoUpgrade bluez-cupsUpgrade bluez-debuginfoUpgrade bluez-debugsourceUpgrade bluez-libs-devel-debuginfoUpgrade bluez-libsUpgrade bluez-deprecated-debuginfo | Sep 30, 2026 | Aug 25, 2026 |
| Redhat_linux | — | No solution exists | Aug 27, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub