What is CVE-2026-16473?
A flaw was found in the sbc library (BlueZ SBC codec) with an off-by-one error in the SBC frame decoder. This allows a crafted audio payload to trigger a one-byte heap out-of-bounds read, potentially enabling an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory. Update the BlueZ SBC codec to the patched version.
Azərbaycanca: SBC kitabxanasında (BlueZ SBC kodeki) "off-by-one" xətası aşkar edilib. Bu, Bluetooth audio axını zamanı xüsusi hazırlanmış yük vasitəsilə heap yaddaşdan bir bayt oxumağa imkan verir. Təsirə məruz qalan sistemlərdə BlueZ SBC kodekinin yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
What type of memory corruption does CVE-2026-16473 cause in the sbc library?
CVE-2026-16473 is an off-by-one error in the BlueZ SBC codec, allowing a crafted audio payload to trigger a one-byte heap out-of-bounds read.
What information can an attacker leveraging CVE-2026-16473 obtain?
An adjacent attacker streaming Bluetooth audio can leverage this flaw to read a single byte of adjacent heap memory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.