THREATOPS
THREAT OPSThreat News › CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)

CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)

lowoss_secPublished 2026-08-14

<p>Posted by Elman Shahbazov on Aug 14</p>Hello,<br /> <br /> I would like to request a CVE ID for an Out-of-Bounds Read vulnerability<br /> (CWE-125) that was recently fixed in the official BlueZ Bluetooth stack.<br /> <br /> Vulnerability Type: CWE-125 (Out-of-bounds Read)<br /> Component: profiles/audio/avrcp.c (AVRCP GetFolderItems parsing)<br /> Impact: A remote Bluetooth device acting as an

Original source: https://seclists.org/oss-sec/2026/q3/498