216.73.217.22

CVE-2026-28527

· Published 30/03/2026 14:16 · Modified 30/03/2026 15:16

Labels: CVE-2026-28527 2026-03-30CVE-2026-28527CWE-125[email protected]

Essential information

Published
30/03/2026 14:16
Modified
30/03/2026 15:16
Author
Creator
CVSS
2.1 LOW (v3) 2.1 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT and GET_PLAYER_APPLICATION_SETTING_VALUE_TEXT handlers that allows nearby attackers to read beyond packet boundaries. Attackers can establish a paired Bluetooth Classic connection and send specially crafted VENDOR_DEPENDENT responses to trigger out-of-bounds reads, causing information disclosure and potential crashes on affected devices.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bluekitchen / btstack cpe:2.3:a:bluekitchen:btstack:*:*:*:*:*:*:*:*

References