CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-75032: Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

mediumCVSS 6.3CVE-2026-75032

CSIRTS triage

What
Bluez contains an out-of-bounds read vulnerability in AVRCP media element and folder parsing functions.
Who is affected
Bluez deployments with AVRCP profiles enabled, reachable via Bluetooth from unpaired or malicious devices.
Urgency
Medium severity (CVSS 6.3) and not exploited; coordinate patching with Bluetooth infrastructure maintenance.
Action
Update Bluez to a version with proper bounds checking in parse_media_element and parse_media_folder functions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Bluez

Get an email when a new Bluez advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 6.3
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-75032

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-75032coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Bluez

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center