Skip to finding
important · Bluetooth

A nearby malicious AVRCP target can drive attacker-controlled stack writes in root-owned bluetoothd 5.87.

Affects

BlueZ 5.87, the Linux Bluetooth userspace stack and its root-owned bluetoothd daemon.

After the victim actively connects, a response count of 255 writes 251 attacker-selected bytes beyond a four-byte stack array and feeds the same count toward a second oversized copy.

Detail and 2 sources

Researchers demonstrated the first overwrite over the air, but not instruction-pointer control on a hardened distribution build.

Chain to watch
Pair a malicious AVRCP target with a hardened BlueZ 5.87 distribution build.→↓Reach the first overwrite and determine whether execution continues into the second copy.→↓Vary attacker-controlled attribute bytes and measure influence over saved control data.→↓Execution through the second overflow and instruction-pointer control on a hardened distribution build remain unproved.
Unverified chainReproduce the exchange on hardened BlueZ 5.87 builds and vary the returned attributes to test second-sink reachability and saved-control-data influence.

No patch was available by the cutoff.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026