High severity8.8NVD Advisory· Published Sep 2, 2022· Updated Apr 15, 2026
CVE-2022-39176
CVE-2022-39176
Description
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
Affected products
4cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Patches
11285bca9bde0Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5- bugs.launchpad.net/ubuntu/+source/bluez/+bug/1977968nvdIssue TrackingPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20221020-0002/nvdThird Party Advisory
- ubuntu.com/security/notices/USN-5481-1nvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlnvd
News mentions
0No linked articles in our index yet.