BlueZ sdp-xml.c Type Confusion in RegisterProfile() leads to Local DoS
CVE-2026-80185 Published on August 25, 2026
Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an Object Type Confusion Vulnerability?
The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CVE-2026-80185 has been classified to as an Object Type Confusion vulnerability or weakness.
Products Associated with CVE-2026-80185
Want to know whenever a new CVE is published for Red Hat Enterprise Linux (RHEL)? stack.watch will email you.