A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile… (CVE-2026-75032)
Description
A vulnerability in BlueZ's Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device to cause an out-of-bounds memory read by sending crafted GetFolderItems responses. This can crash the bluetoothd daemon, resulting in a denial of service, and may expose sensitive heap memory. Exploitation requires user interaction to pair with the malicious device. Multiple affected Ubuntu package versions exist, and patches have been released.
CVSS v3.1
Score 6.3medium
Affected software
pkg:deb/ubuntu/bluez?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/bluez?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/bluez?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/bluez?arch=source&distro=jammypkg:deb/ubuntu/bluez?arch=source&distro=noblepkg:deb/ubuntu/bluez?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-75032 is a vulnerability in BlueZ where insufficient validation of packet length fields in GetFolderItems responses within the AVRCP implementation leads to out-of-bounds memory reads. The flaw affects the parse_media_element() and parse_media_folder() functions. A malicious Bluetooth device within range can exploit this by pairing with the target device, causing the bluetoothd daemon to crash (DoS) and potentially leaking sensitive heap memory contents. The vulnerability has a CVSS 3.1 score of 6.3 (medium severity) and affects multiple Ubuntu BlueZ package versions prior to patched releases. Official patches are available from Ubuntu.
Potential Impact
Successful exploitation can cause the bluetoothd daemon to crash, resulting in denial of service. Additionally, it may expose sensitive heap memory contents, potentially leaking information. Exploitation requires user interaction to pair with a malicious Bluetooth device within range.
Mitigation Recommendations
A patch is available and should be applied by updating BlueZ to the fixed package versions provided by Ubuntu. The vendor advisory (USN-8908-1) confirms that standard system updates will apply the necessary fixes. Users should ensure their systems are updated to the patched BlueZ versions to remediate this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-75032
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6ac96e642cdf04f65689a91f
Added to database: 10/09/2026, 22:44:52 UTC
Last enriched: 10/09/2026, 22:54:38 UTC
Last updated: 10/09/2026, 22:54:38 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.