← Back to CVE List
CVE-2026-93015NVD
Vulnerability Summary
BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.
CVSS v4.0 Base Metrics — Score 7.0 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityHigh
Affected & Patched Versions
- BlueKitchen GmbH BTstack <= 1.8.2
- BlueKitchen GmbH BTstack 1.8.2
External References
- https://github.com/bluekitchen/btstack/commit/fc208fcce056d4e0a5bb916abc90e83a383e1cdf
- https://github.com/bluekitchen/btstack/blob/v1.8.2/src/classic/a2dp.c#L568
- https://github.com/bluekitchen/btstack/blob/v1.8.2/src/classic/avdtp.c#L1703
- https://github.com/bluekitchen/btstack
- https://www.vulncheck.com/advisories/bluekitchen-btstack-through-1.8.2-a2dp-sep-discovery-out-of-bounds-write