BlueZ是BlueZ组织开源的一个蓝牙协议栈软件。 BlueZ存在缓冲区错误漏洞,该漏洞源于AVRCP实现中GetFolderItems响应的数据包长度字段验证不足,影响parse_media_element()和parse_media_folder()函数,可能导致越界内存读取,进而导致bluetoothd守护进程崩溃,造成拒绝服务,并可能泄露敏感堆内存内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12564 | 9.6 CRITICAL | Automation-controller: automation-controller: kubernetes service account token exfiltratio |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-75924 | 8.7 HIGH | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants clust |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66780 | 6.5 MEDIUM | Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace ver |
| CVE-2026-66782 | 5.8 MEDIUM | Submariner-operator: operator clusterrole grants cluster-wide create/update on all configm |
| CVE-2026-75485 | 5.5 MEDIUM | Must-gather: /tmp/kubeconfig retention |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-66781 | 5.4 MEDIUM | Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authe |
| CVE-2026-19608 | 5.3 MEDIUM | Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy |
| CVE-2026-66783 | 4.4 MEDIUM | Submariner-operator: release workflow consumes same-org composite action via mutable @deve |
No comments yet