CVE-2026-101887

CVE & Vulnerabilities · October 3, 2026

CVE & Vulnerabilities·nvd.nist.gov

A division-by-zero bug in BlueALSA's LC3plus audio decoder lets a nearby Bluetooth attacker crash the bluealsad daemon. By pairing as an A2DP source and negotiating an LC3plus stream against a device acting as sink, an attacker can send a crafted RTP media header with the frame-count field zeroed out to trigger the crash. The flaw sits in the a2dp_lc3plus_dec_thread handler and needs only Bluetooth proximity, not authentication.

// source: nvd.nist.gov ↗

← Back to Blog