Executive brief
BlueKitchen BTstack is a software library used to provide Bluetooth connectivity for embedded systems and resource-constrained devices. A vulnerability in how it handles media player control messages could allow a nearby attacker to crash a device. To exploit this, an attacker must be within Bluetooth range and have an established connection with the target device.
Technical details
An out-of-bounds read vulnerability exists in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATTRIBUTES and LIST_PLAYER_APPLICATION_SETTING_VALUES handlers within BlueKitchen BTstack. The flaw is rooted in insufficient validation of an attacker-controlled 'count' value within a VENDOR_DEPENDENT response. A nearby attacker with an existing paired Bluetooth Classic connection can send a specially crafted response to trigger a read beyond the L2CAP receive buffer boundaries. This can lead to a denial-of-service (crash), particularly on resource-constrained hardware. The issue is addressed in version 1.8.1.
Affected products
- BlueKitchen BTstack < 1.8.1
Timeline
- 2026-03-25: patched: Version 1.8.1 released on GitHub.
- 2026-03-30: disclosed: Initial advisory published.