Back to vendor advisories
Ubuntu Security NoticesUSN-8908-1

USN-8908-1: BlueZ vulnerabilities

Severity not listed 5 CVEs Published Oct 8, 2026 at 9:50 PM UTC

Summary

Michael Bommarito discovered that BlueZ incorrectly handled codec capability storage in the A2DP profile. An attacker could possibly use this issue to cause a stack buffer overflow, resulting in a denial of service or arbitrary code execution. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-19774)

It was discovered that BlueZ incorrectly handled packet length validation. An attacker could possibly use this issue to read out of bounds memory, causing a crash or exposing sensitive information. (CVE-2026-75032)

It was discovered that BlueZ incorrectly handled crafted XML input. An attacker could possibly use this issue to crash BlueZ, resulting in a denial of service. (CVE-2026-80185)

It was discovered that BlueZ incorrectly parsed remote names from Extended Inquiry Response data. An attacker could possibly use this issue to cause a stack buffer overflow, resulting in a denial of service or arbitrary code execution. (CVE-2026-80186)

Alexandro Calo discovered that BlueZ incorrectly parsed certain responses in the AVRCP profile. An attacker could possibly use this issue to access out of bounds memory, causing a crash or exposing sensitive information. (CVE-2026-85218)

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 5

Updates

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.