Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80185— Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BlueZ 中的 sdp-xml.c 存在类型混淆漏洞(通过 RegisterProfile(ServiceRecord) 触发),可导致 bluetoothd 崩溃(本地拒绝服务):构造的嵌套 ServiceRecord 会破坏 SDP XML 解析器的栈,使得标量联合(scalar union)数据被误当作序列指针处理,从而允许本地调用者导致 bluetoothd 崩溃。

CVSS 5.7 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root
Source: CVE Program / CVE List V5
Vulnerability Description
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-80185

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80185

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80185 (2)

Same Patch Batch · Red Hat · 2026-08-25 · 10 CVEs total

CVE-2026-79992 7.8 HIGH Emacs: local shell command injection through the user field in emacs tramp
CVE-2026-79655 7.8 HIGH Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targ
CVE-2026-80186 7.6 HIGH Bluez: stack overflow in name2utf8 causes dos and potential code execution
CVE-2026-78701 6.5 MEDIUM 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall d
CVE-2026-78322 6.5 MEDIUM File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar hand
CVE-2026-79717 6.4 MEDIUM Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restrict
CVE-2026-79652 5.9 MEDIUM Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce cons
CVE-2026-77680 5.3 MEDIUM Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025
CVE-2026-80101 4.4 MEDIUM Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l

IV. Related Vulnerabilities

V. Comments for CVE-2026-80185

No comments yet


Leave a comment