Multiple Vulnerabilities in BlueZ Affect Fedora Users

Multiple Vulnerabilities in BlueZ Affect Fedora Users

First seen 29 Aug 2026, 13:49 UTC Linuxsecurity 57.1

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in BlueZ, the Linux Bluetooth protocol stack, affect Fedora systems. CVE-2026-80186 and CVE-2026-80185, published on August 25, 2026, involve a stack-based buffer overflow and local denial of service (DoS) that could allow arbitrary code execution. Additionally, CVE-2026-75032, published on August 18, 2026, presents an out-of-bounds read flaw in the AVRCP profile, also leading to DoS. These vulnerabilities can be exploited by remote users within Bluetooth range by sending specially crafted packets. Users are advised to update their systems using the provided dnf commands to mitigate these risks. The vulnerabilities have been confirmed and patched, but the potential for exploitation remains a concern.

Key Points: • Three critical CVEs affect BlueZ in Fedora: CVE-2026-80186, CVE-2026-80185, and CVE-2026-75032. • Exploitation can lead to denial of service and potential arbitrary code execution. • Users are urged to apply updates immediately to secure their systems.

Timeline

2026-08-18
CVE-2026-75032 published
An out-of-bounds read flaw in BlueZ's AVRCP profile allows potential DoS and exposure of sensitive data.
Linuxsecurity
2026-08-25
CVE-2026-80186 and CVE-2026-80185 published
Two vulnerabilities in BlueZ lead to a stack-based buffer overflow and local DoS, potentially allowing arbitrary code execution.
Linuxsecurity
2026-08-26
Patches released for vulnerabilities
Updates were released to fix CVE-2026-80186 and CVE-2026-80185, addressing critical security flaws in BlueZ.
Linuxsecurity