CVE-2026-79377
massHeap overflow in Bestechnic BES2300 Bluetooth audio SoC firmware allows DoS
CVE-2026-79377 is a heap-based buffer overflow (CWE-122) in the SBC decoder component (a2dp_decoder_sbc.cpp) of the firmware for Bestechnic's BES2300 Bluetooth audio SoC, versions v3.x and earlier. An attacker within Bluetooth range can trigger it by sending a specially crafted L2CAP packet that the SBC A2DP decoder mishandles, overwriting heap memory. The practical impact is a crash of the audio firmware, i.e., a denial of service of the audio device; the CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity loss. Affected parties are users of consumer Bluetooth audio products (such as earbuds, headphones, and speakers) built on the BES2300 SoC and running firmware v3.x or earlier, where the fix depends on the device OEM shipping updated firmware. Exploitation status: no public PoC, not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Check which of your Bluetooth audio products use a BES2300 SoC and apply updated firmware from the device manufacturer once it ships a release beyond v3.x, as fixes come through OEM firmware updates rather than a patch you can install directly. Note that exploitation requires an attacker within Bluetooth radio range, so remote mass exploitation is unlikely; the EPSS of 0.4% and absence of a public PoC indicate low immediate risk. Monitor OEM and Bestechnic advisories for patched firmware versions and update devices when available.
| Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware | v3.x and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.