important · Bluetooth
A nearby malicious AVRCP target can drive attacker-controlled stack writes in root-owned bluetoothd 5.87.
Affects
BlueZ 5.87, the Linux Bluetooth userspace stack and its root-owned bluetoothd daemon.
After the victim actively connects, a response count of 255 writes 251 attacker-selected bytes beyond a four-byte stack array and feeds the same count toward a second oversized copy.
Detail and 2 sources
Researchers demonstrated the first overwrite over the air, but not instruction-pointer control on a hardened distribution build.
Chain to watch
Pair a malicious AVRCP target with a hardened BlueZ 5.87 distribution build.→↓Reach the first overwrite and determine whether execution continues into the second copy.→↓Vary attacker-controlled attribute bytes and measure influence over saved control data.→↓Execution through the second overflow and instruction-pointer control on a hardened distribution build remain unproved.
Unverified chainReproduce the exchange on hardened BlueZ 5.87 builds and vary the returned attributes to test second-sink reachability and saved-control-data influence.
No patch was available by the cutoff.