Executive brief
BlueKitchen BTstack is a software library used to provide Bluetooth connectivity for embedded systems and devices. A security flaw in how the software handles media player settings could allow a nearby attacker to crash the device or potentially access sensitive information from its memory. To exploit this, an attacker must be within Bluetooth range and establish a connection with the target device.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the AVRCP Controller component of BlueKitchen BTstack. The flaw is located within the GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT and GET_PLAYER_APPLICATION_SETTING_VALUE_TEXT handlers. A nearby attacker can exploit this by establishing a paired Bluetooth Classic connection and sending specially crafted VENDOR_DEPENDENT responses. This triggers a read beyond packet boundaries, leading to information disclosure or a denial-of-service (crash). The issue is resolved in version 1.8.1.
Affected products
- BlueKitchen BTstack < 1.8.1
Timeline
- 2026-03-25: patched: Version 1.8.1 released
- 2026-03-30: advisory: Initial disclosure by VulnCheck