CVE-2026-28528 Details
Description
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET_FOLDER_ITEMS handler that fails to validate packet boundaries and attribute count data. An attacker with a paired Bluetooth Classic connection can exploit insufficient bounds checking on the attr_id parameter to cause crashes and corrupt attribute bitmap state.
A out-of-bounds read vulnerability has been identified in BlueKitchen BTstack versions prior to 1.8.1. The issue arises in the AVRCP Browsing Target GET_FOLDER_ITEMS handler, which does not properly validate packet boundaries or attribute count data. This vulnerability can be exploited by an attacker with a paired Bluetooth Classic connection, taking advantage of inadequate bounds checking on the attr_id parameter. Exploitation can lead to crashes and corruption of the attribute bitmap state.
Users can upgrade to BlueKitchen BTstack version 1.8.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-758 | Reliance on Undefined, Unspecified, or Implementation-Defined Behavior | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bluekitchen-gmbh btstack | < 1.8.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | CVE Modified | [email protected] |
| Mar 30, 2026 | New CVE Received | [email protected] |