ZeroHour

CVE-2026-79377

mass

Heap overflow in Bestechnic BES2300 Bluetooth audio SoC firmware allows DoS

CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-79377 is a heap-based buffer overflow (CWE-122) in the SBC decoder component (a2dp_decoder_sbc.cpp) of the firmware for Bestechnic's BES2300 Bluetooth audio SoC, versions v3.x and earlier. An attacker within Bluetooth range can trigger it by sending a specially crafted L2CAP packet that the SBC A2DP decoder mishandles, overwriting heap memory. The practical impact is a crash of the audio firmware, i.e., a denial of service of the audio device; the CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss. Affected parties are users of consumer Bluetooth audio products (such as earbuds, headphones, and speakers) built on the BES2300 SoC and running firmware v3.x or earlier, where the fix depends on the device OEM shipping updated firmware. Exploitation status: no public PoC, not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.

What to do: Check which of your Bluetooth audio products use a BES2300 SoC and apply updated firmware from the device manufacturer once it ships a release beyond v3.x, as fixes come through OEM firmware updates rather than a patch you can install directly. Note that exploitation requires an attacker within Bluetooth radio range, so remote mass exploitation is unlikely; the EPSS of 0.4% and absence of a public PoC indicate low immediate risk. Monitor OEM and Bestechnic advisories for patched firmware versions and update devices when available.

Affected
Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmwarev3.x and earlier
Estimated exposure
masslikely millions of consumer Bluetooth audio devices (no official install-base figures published) — Bestechnic's BES2300 is a commonly used Bluetooth audio SoC deployed across many consumer earbud, headphone, and speaker brands, implying a multi-million-device installed base, though exact unit counts and the firmware-version split are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.