Junglewise Threat Intelligence

CVE-2026-28526: BlueKitchen BTstack out-of-bounds read in AVRCP Controller

CVE-2026-28526 · Severity: low · CVSS 3.5 · Published 2026-03-30

Technologies: Bluekitchen-Gmbh Btstack. Vendors: Bluekitchen-Gmbh.

Executive brief

BlueKitchen BTstack is a software library used to provide Bluetooth connectivity for embedded systems and resource-constrained devices. A vulnerability in how it handles media player control messages could allow a nearby attacker to crash a device. To exploit this, an attacker must be within Bluetooth range and have an established connection with the target device.

Technical details

An out-of-bounds read vulnerability exists in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATTRIBUTES and LIST_PLAYER_APPLICATION_SETTING_VALUES handlers within BlueKitchen BTstack. The flaw is rooted in insufficient validation of an attacker-controlled 'count' value within a VENDOR_DEPENDENT response. A nearby attacker with an existing paired Bluetooth Classic connection can send a specially crafted response to trigger a read beyond the L2CAP receive buffer boundaries. This can lead to a denial-of-service (crash), particularly on resource-constrained hardware. The issue is addressed in version 1.8.1.

Affected products

  • BlueKitchen BTstack < 1.8.1

Timeline

  • 2026-03-25: patched: Version 1.8.1 released on GitHub.
  • 2026-03-30: disclosed: Initial advisory published.

References

Related threats