← Vulnerability feed

Vulnerability record · CVE-2023-50229 · published 3 May 2024

CVE-2023-50229: Bluez heap-based buffer overflow vulnerability

Bluez · Bluez

BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20936.

8.0 CVSS 3.1 High EPSS 2.3% · top 17.5% CWE-122 · Heap-based buffer overflow
8.0CVSS 3.1 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20936.

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-50229 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-43400Bluez use after free vulnerabilityAn issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…EPSS 1.7%8.8CVE-2024-8805Bluez improper access control vulnerabilityBlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to exec…EPSS 2.0%8.8CVE-2022-39176Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.EPSS 0.71%8.8CVE-2022-39177Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p…EPSS 0.67%8.8CVE-2022-0204Bluez memory buffer overflow vulnerabilityA heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files …EPSS 1.8%8.8CVE-2019-8922Bluez out-of-bounds write vulnerabilityA heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin…EPSS 1.5%8.6CVE-2020-27153Bluez double free vulnerabilityIn BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a …EPSS 4.3%8.0CVE-2023-50230Bluez heap-based buffer overflow vulnerabilityBlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-50229), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.