CVE-2026-80186
Awaiting Analysis Awaiting Analysis - Queue

Stack-Based Buffer Overflow in BlueZ Bluetooth Stack

Vulnerability report for CVE-2026-80186, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-27

Assigner: redhat-SADP

Description

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-27
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-13
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bluez bluez *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in BlueZ, the Linux Bluetooth protocol stack. A remote attacker within Bluetooth range can exploit it by sending a specially crafted Extended Inquiry Response (EIR) packet. When the target device performs Bluetooth discovery, the overflow occurs, potentially crashing the bluetoothd service and allowing arbitrary code execution.

Detection Guidance

Detecting this vulnerability requires monitoring for Bluetooth discovery processes and potential crashes in the bluetoothd service. Check if the bluetoothd service is running and monitor for unexpected crashes or errors during Bluetooth discovery operations.

Impact Analysis

This vulnerability could allow an attacker to crash your device's Bluetooth service, causing a Denial of Service. In some cases, it may also enable arbitrary code execution, which could lead to unauthorized access or control of your system if exploited.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized code execution or service disruption on Bluetooth-enabled devices. A DoS condition or arbitrary code execution may lead to data breaches or unauthorized access, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Disable Bluetooth discovery if not needed, update BlueZ to the latest patched version, and restrict Bluetooth access to trusted devices only. Apply firewall rules to limit Bluetooth traffic if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80186. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart