VYPR
High severity8.8NVD Advisory· Published Sep 2, 2022· Updated Apr 15, 2026

CVE-2022-39176

CVE-2022-39176

Description

BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.

Affected products

4
  • cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*
    Range: <5.59
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.