CVE-2026-93015
BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.
| CWE | CWE-787 CWE-1284 |
| Vendor | bluekitchen gmbh |
| Product | btstack |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for bluekitchen gmbh btstack
Be the first to know when new medium vulnerabilities affecting bluekitchen gmbh btstack are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Affected Versions
BlueKitchen GmbH / BTstack
0 โค 1.8.2
References
github.com: https://github.com/bluekitchen/btstack/commit/fc208fcce056d4e0a5bb916abc90e83a383e1cdf github.com: https://github.com/bluekitchen/btstack/blob/v1.8.2/src/classic/a2dp.c#L568 github.com: https://github.com/bluekitchen/btstack/blob/v1.8.2/src/classic/avdtp.c#L1703 github.com: https://github.com/bluekitchen/btstack vulncheck.com: https://www.vulncheck.com/advisories/bluekitchen-btstack-through-1.8.2-a2dp-sep-discovery-out-of-bounds-write
Credits
Eun0us / Espilon VulnCheck