CVE-2023-27349
published 2024-05-03CVE-2023-27349: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to…
PriorityP347high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
EPSS
1.43%
70.0th percentile
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.
The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bluez | bluez | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u2 | 5.55-3.1+deb11u2 |
| bluez | bluez | >= 0 < 5.66-1+deb12u2 | 5.66-1+deb12u2 |
| bluez | bluez | >= 0 < 5.68-1 | 5.68-1 |
| bluez | bluez | >= 0 < 5.68-1 | 5.68-1 |
| bluez | bluez | >= 0 < 5.53-0ubuntu3.8 | 5.53-0ubuntu3.8 |
| bluez | bluez | >= 0 < 5.64-0ubuntu1.3 | 5.64-0ubuntu1.3 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.3+esm4 | 5.37-0ubuntu5.3+esm4 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.9+esm2 | 5.48-0ubuntu3.9+esm2 |
| debian | bluez | < bluez 5.66-1+deb12u2 (bookworm) | bluez 5.66-1+deb12u2 (bookworm) |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.0HIGH
vendor_debian8.0HIGH
vendor_oracle8.0HIGH
vendor_redhat8.0HIGH
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bluez vulnerabilities
osv·2024-06-05·CVSS 5.7
CVE-2022-3563 [MEDIUM] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ could be made to dereference invalid memory.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 22.04 LTS. (CVE-2022-3563)
It was discovered that BlueZ could be made to write out of bounds. If a
user were tricked into connecting to a malicious device, an attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2023-27349)
OSV
CVE-2023-27349: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
osv·2024-05-03·CVSS 8.0
CVE-2023-27349 [HIGH] CVE-2023-27349: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
GHSA
GHSA-r3vg-5hjq-528v: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
ghsa_unreviewed·2024-05-03
CVE-2023-27349 [HIGH] CWE-129 GHSA-r3vg-5hjq-528v: BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.
The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Oracle
Oracle Oracle Communications Risk Matrix: Platform Security (BlueZ) — CVE-2023-27349
vendor_oracle·2025-07-15·CVSS 8.0
CVE-2023-27349 [HIGH] Oracle Oracle Communications Risk Matrix: Platform Security (BlueZ) — CVE-2023-27349
Oracle Oracle Communications Risk Matrix: Platform Security (BlueZ) vulnerability
CVE: CVE-2023-27349
CVSS: 8.0
Protocol: Multiple
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujul2025 (JUL 2025)
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 3.5
CVE-2023-27349 [LOW] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ could be made to dereference invalid memory.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 22.04 LTS. (CVE-2022-3563)
It was discovered that BlueZ could be made to write out of bounds. If a
user were tricked into connecting to a malicious device, an attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2023-27349)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
BlueZ: Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
vendor_redhat·2024-05-03·CVSS 8.0
CVE-2023-27349 [HIGH] CWE-129 BlueZ: Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
BlueZ: Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.
The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
A vulnerability was found in the BlueZ Audio Pr
Debian
CVE-2023-27349: bluez - BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Executi...
vendor_debian·2023·CVSS 8.0
CVE-2023-27349 [HIGH] CVE-2023-27349: bluez - BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Executi...
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
Scope: local
bookworm: resolved (fixed in 5.66-1+deb12u2)
bullseye: resolved (fixed in 5.55-3.1+deb11u2)
forky: resolved (fixed in 5.68-1)
sid: res
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVEs, su
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVE
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=f54299a850676d92c3dafd83e9174fcfe420ccc9https://lists.debian.org/debian-lts-announce/2024/05/msg00015.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-23-386/https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=f54299a850676d92c3dafd83e9174fcfe420ccc9https://lists.debian.org/debian-lts-announce/2024/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-23-386/
2024-05-03
Published