USN-8908-1: BlueZ vulnerabilities
Ubuntu patched BlueZ flaws, including an A2DP stack overflow and an out-of-bounds memory read.
Ubuntu USN-8908-1 fixes vulnerabilities in BlueZ, the Linux Bluetooth stack. Michael Bommarito found that A2DP codec-capability handling can cause a stack buffer overflow, tracked as CVE-2026-19774, which may lead to denial of service or code execution on Ubuntu 20.04, 22.04, 24.04, and 26.04 LTS. A packet-length validation flaw, CVE-2026-75032, can read out-of-bounds memory and crash the process or expose data. The notice also describes a crafted-XML crash issue, but the excerpt ends before naming that CVE.
- CVE-2026-19774 is an A2DP stack buffer overflow in BlueZ.
- It could cause denial of service or arbitrary code execution.
- CVE-2026-75032 is an out-of-bounds read via packet length checks.
- A crafted-XML crash issue is mentioned, but its CVE is truncated.
- No active exploitation is reported in the notice.
Vulnerabilities mentionedAll →
- CVE-2026-197747.1—BlueZ A2DP Stack-Based Buffer Overflow Enables Root RCE via Malicious Bluetooth Pairingpublished · BlueZ project BlueZ (Bluetooth protocol stack, A2DP stream endpoint handling)
- CVE-2026-750326.3<1%BlueZ: Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP)…published
Michael Bommarito discovered that BlueZ incorrectly handled codec capability storage in the A2DP profile. An attacker could possibly use this issue to cause a stack buffer overflow, resulting in a denial of service or arbitrary code execution. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-19774) It was discovered that BlueZ incorrectly handled packet length validation. An attacker could possibly use this issue to read out of bounds memory, causing a crash or exposing sensitive information. (CVE-2026-75032) It was discovered that BlueZ incorrectly handled crafted XML input. An attacker could possibly use this issue to crash…
This source does not provide full text. Read it at ubuntu.com.