#1144961 bluez: CVE-2026-75032

Package:
src:bluez
Source:
src:bluez
Submitter:
Salvatore Bonaccorso
Date:
2026-08-21 16:41:03 UTC
Severity:
normal
Tags:
#1144961#5
Date:
2026-08-20 19:34:08 UTC
From:
To:
Hi,

The following vulnerability was published for bluez.

CVE-2026-75032[0]:
| A flaw was found in BlueZ. Insufficient validation of packet length
| fields in GetFolderItems responses within the Audio/Video Remote
| Control Profile (AVRCP) implementation allows a malicious Bluetooth
| device within range to cause an out-of-bounds memory read. This
| vulnerability, affecting the parse_media_element() and
| parse_media_folder() functions, can lead to a crash of the
| bluetoothd daemon, resulting in a Denial of Service (DoS). It could
| also potentially expose sensitive heap memory contents. Exploitation
| requires user interaction to pair with the malicious device.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75032
https://www.cve.org/CVERecord?id=CVE-2026-75032
[1] https://github.com/bluez/bluez/commit/bd8989620ed6e80755f06cfdb18f5b4a3913493c
[2] https://github.com/bluez/bluez/commit/58088149872d014684a582fdb7ad01a5180c9bc5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144961#10
Date:
2026-08-21 16:39:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
bluez, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144961@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated bluez package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 17:59:48 +0200
Source: bluez
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 5.87-2
Distribution: unstable
Urgency: high
Maintainer: Debian Bluetooth Maintainers <team+pkg-bluetooth@tracker.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1144961
Changes:
 bluez (5.87-2) unstable; urgency=high
 .
   * Team upload
   * SECURITY UPDATE: out of bounds read
     - debian/patches/CVE-2026-75032-part1.patch
       debian/patches/CVE-2026-75032-part2.patch
       Fix out-of-bounds read in AVRCP GetFolderItems parsing
       in profiles/audio/avrcp.c
     - CVE-2026-75032 (Closes: #1144961)
Checksums-Sha1:
 a3c3e7ea3b881274a6a91db1aa6dfe6a8c3dd4c5 2850 bluez_5.87-2.dsc
 b0f6ac7bc7a17dff3b5f1b316cab8bdd201ed99e 38296 bluez_5.87-2.debian.tar.xz
 35fc4d64ac54573ba7d061e2859f76db3322d51d 8147 bluez_5.87-2_source.buildinfo
Checksums-Sha256:
 5d2dff80e6af0fefb6d41b76d14472f05d8fb2be8e7c3c4d040ef3c59515f40f 2850 bluez_5.87-2.dsc
 ff489508dbb7aed702f11207dc0721c33f728d93bf8499e375e72ddfc885da01 38296 bluez_5.87-2.debian.tar.xz
 4bf5c6eb3c350dab0ff68369fdc7ee7bdccfa74c32983c383c31bfd3c3726981 8147 bluez_5.87-2_source.buildinfo
Files:
 49b630f43c1c3db40193c16b6ff8d811 2850 admin optional bluez_5.87-2.dsc
 228cbdddfa8edf9165b7cf00325c31c6 38296 admin optional bluez_5.87-2.debian.tar.xz
 115e84e2205a2cac19791216fe03ad5a 8147 admin optional bluez_5.87-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIdkAACgkQ5mx3Wuv+
bH1GcBAAirpknmBLbraJlA3sV1/HlXquT77q9HhtKjM1gqY+7CDWzateIBSysp8b
PDnUkGpQumSNVBA2eKHWXaF98tVHwZPg+r4aVFT45gRd+mu7BTgh5p0DnWuhnzK+
onP07kpdIMpOgcweiLpGUjoOlPY23S1SS9mW0QXsjtLUwHN9/jkKMHI2aKf0RiFh
HAM+fHpg73eaN8vIxYKEROSIXaCVX123oS0FDK25DqXVHafBtBo09uIYcGeXBOFk
jUx6uGJIVeZeAiHF9MIvphdYT6Y/Mv5kdAzS3YSS2YspS17JC2ayarUYl5Y9ASQS
2p43lDyzdXPpbRYl41fZWIQiJ4/LUc/5FbHJ9XtqI3yH1yQDxDzndwpvHzVw6WJW
IeaNXHObi+hC/WW336EFi4PK+5pPs/280Lz66co9UtC5VkrSDvnUirLBeBVgbXKT
WijCxekkQ9Bkg7mI6PQJ1VurU4u7MQXExeQSUvOVxU+gEUG8cQY5ECrg8uun9/VI
cl5Oa/P7Ayx4rxM6wJ1pQcsHtAWn9Sb0tBOgdMsIy9C0mNMntsczbvTmVe3KgYWE
x/oes8Ps+7nI81mgzHEWIriVqVRqVIaSSUvJ/BtoKAA2BcZd/d/sQITsb77fcCje
7GFYlBP1x+hu/WzELBoDZhnxQjcuU4Q5F7hxbrROpyZE3ihD0rA=
=kUke
-----END PGP SIGNATURE-----