#1145869 bluez; CVE-2026-80186

#1145869#5
Date:
2026-08-27 12:40:50 UTC
From:
To:
Hi,

The following vulnerability was published for bluez.

CVE-2026-80186[0]:
| A stack-based buffer overflow vulnerability exists in BlueZ, the
| Linux Bluetooth protocol stack. A remote user within Bluetooth radio
| range can send a specially crafted Extended Inquiry Response (EIR)
| packet that causes a buffer overflow when the target device performs
| Bluetooth discovery. This vulnerability can lead to a Denial of
| Service (DoS) by crashing the bluetoothd service and may allow for
| arbitrary code execution.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-80186
https://www.cve.org/CVERecord?id=CVE-2026-80186
[1] https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
[2] https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore