CVE-2026-79377 Details
Description
A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
A heap overflow vulnerability has been identified in the Bestechnic BES2300 Bluetooth Audio SoC firmware versions through 3.x. This vulnerability resides in the L2CAP layer, where the absence of proper bounds checking allows attackers to cause a denial-of-service by sending crafted L2CAP packets. The vulnerability can be exploited by transmitting a sequence of CONTINUE fragments that exceed the allocated buffer size, leading to memory corruption and potential remote code execution.
Users are advised to upgrade to version 5.0 / RC06 or later, as this version addresses the vulnerability by implementing proper bounds checks and reassembly buffer management. For those unable to upgrade immediately, a reference patch is available to add the necessary bounds checking before processing L2CAP packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Derek-Vencer/best1307/blob/296d587ad3766bbff96e7f466cf0775c170a/apps/audioplayers/a2dp_decoder/a2dp_decoder_sbc.cpp | [email protected] | Source Code |
| https://www.bestechnic.com/CVE-2026-79376.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Bestechnic BES2300 | <v3.0 = v3.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion