USN-8908-1: BlueZ vulnerabilities
Ubuntu patched BlueZ flaws, including an A2DP stack overflow and an out-of-bounds memory read.
Ubuntu USN-8908-1 fixes vulnerabilities in BlueZ, the Linux Bluetooth stack. Michael Bommarito found that A2DP codec-capability handling can cause a stack buffer overflow, tracked as CVE-2026-19774, which may lead to denial of service or code execution on Ubuntu 20.04, 22.04, 24.04, and 26.04 LTS. A packet-length validation flaw, CVE-2026-75032, can read out-of-bounds memory and crash the process or expose data. The notice also describes a crafted-XML crash issue, but the excerpt ends before naming that CVE.