BlueZ is the Linux Bluetooth protocol stack and utilities suite, a foundational component deeply embedded in Linux distributions and numerous Bluetooth-enabled devices across consumer electronics, IoT platforms, and embedded systems. Despite a narrow product footprint, its position as the de facto Bluetooth implementation for Linux grants it prominence across a broad deployment landscape. Vulnerabilities affecting BlueZ skew toward meaningful severity outcomes and recur through memory-safety and resource-management weakness classes including buffer overflows, out-of-bounds reads, and improper bounds checking, reflecting the low-level parsing and state-machine complexity inherent to Bluetooth protocol handling. Defenders should treat BlueZ advisories as broadly applicable to Linux-based deployments and prioritize Bluetooth-exposed devices; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluez over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2374CRITICAL src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows re | Jul 7, 2008 | 9.8 | 32 | NO | NO |
CVE-2020-12352MEDIUM Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | Nov 23, 2020 | 6.5 | 30 | NO | YES |
CVE-2021-43400CRITICAL An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call. | Nov 4, 2021 | 9.1 | 29 | NO | NO |
CVE-2020-27153HIGH In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execu | Oct 15, 2020 | 8.6 | 29 | NO | NO |
CVE-2022-39177HIGH BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c. | Sep 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-39176HIGH BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len. | Sep 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-8805HIGH BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected | Nov 22, 2024 | 8.8 | 27 | NO | NO |
CVE-2017-1000250MEDIUM All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information fro | Sep 12, 2017 | 6.5 | 26 | NO | NO |
CVE-2016-9918HIGH In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file | Dec 8, 2016 | 7.5 | 26 | NO | NO |
CVE-2016-9917HIGH In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result | Dec 8, 2016 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluez.
Media articles that mention a CVE ID that affects a product developed by Bluez — matched by CVE ID, not by vendor name.