CVE-2026-16473EPSS p20.4%
CVE-2026-16473CVE-2026-16473
Description
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.30% probability of exploitation · percentile 20.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |