CVE-2026-16473 Details
Description
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
A heap out-of-bounds read vulnerability has been identified in the BlueZ SBC codec library, specifically in versions 1.0 through 2.0. The issue arises from an off-by-one error in the SBC frame decoder, where the bit-reader's boundary check allows a crafted audio payload to read one byte beyond the intended buffer limit. This flaw can be exploited by an adjacent attacker streaming Bluetooth audio, potentially leading to the disclosure of a single byte from adjacent heap memory.
Red Hat has deferred the fix for this vulnerability in all affected versions of the sbc package. As a temporary measure, Bluetooth A2DP audio decoding can be disabled, although this is not a practical long-term solution.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |