Package "libbluetooth3"
| Name: |
libbluetooth3
|
Description: |
Library to use the BlueZ Linux Bluetooth stack
|
| Latest version: |
5.72-0ubuntu5.7 |
| Release: |
noble (24.04) |
| Level: |
updates |
| Repository: |
main |
| Head package: |
bluez |
| Homepage: |
http://www.bluez.org |
Links
Download "libbluetooth3"
Other versions of "libbluetooth3" in Noble
Changelog
|
bluez (5.72-0ubuntu5.7) noble-security; urgency=medium
* SECURITY UPDATE: stack-based buffer overflow
- debian/patches/CVE-2026-19774.patch: a2dp: Fix handling of codec
capability storage in profiles/audio/a2dp.c.
- CVE-2026-19774
* SECURITY UPDATE: out-of-bounds read
- debian/patches/CVE-2026-75032_1.patch: avrcp: Fix Out-of-Bounds Read in
AVRCP GetFolderItems parsing in profiles/audio/avrcp.c.
- debian/patches/CVE-2026-75032_2.patch: avrcp: Fix media/folder name not
being set in profiles/audio/avrcp.c.
- CVE-2026-75032
* SECURITY UPDATE: type confusion
- debian/patches/CVE-2026-80185.patch: sdp-xml: Fix crash caused by type
confusion when parsing crafted SDP XML in src/sdp-xml.c.
- CVE-2026-80185
* SECURITY UPDATE: stack-based buffer overflow
- debian/patches/CVE-2026-80186.patch: eir: Fix stack buffer overflow when
parsing the remote name in src/eir.c.
- CVE-2026-80186
* SECURITY UPDATE: out-of-bounds access
- debian/patches/CVE-2026-85218.patch: avrcp: Fix out-of-bounds parsing of
ListPlayerAttributes response in profiles/audio/avrcp.c.
- CVE-2026-85218
-- Allen Huang Wed, 07 Oct 2026 21:29:45 +0100
|
| Source diff to previous version |
| CVE-2026-19774 |
BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary |
| CVE-2026-75032 |
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile |
| CVE-2026-80185 |
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SD |
| CVE-2026-80186 |
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send |
|
|
bluez (5.72-0ubuntu5.6) noble; urgency=medium
[ Balachandra Bhat ]
* d/patches: Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA
(LP: #2164626)
-- Daniel van Vugt Tue, 22 Sep 2026 15:09:58 +0800
|
| Source diff to previous version |
| 2164626 |
[SRU][Resolute] Fix sending extra bytes with MGMT_OP_ADD_EXT_ADV_DATA |
|
|
bluez (5.72-0ubuntu5.5) noble; urgency=medium
[ Dirk Su ]
* Improve audio profiles compatibility (LP: #2122382)
d/patches: audio-upgrade-versions-to-latest-possible-to-qualify.patch
d/patches: cleanup-endpoints-when-devices-been-removed.patch
d/patches: profiles-avdtp-Fix-reply-for-bad-media-transport-for.patch
-- Daniel van Vugt <email address hidden> Wed, 08 Oct 2025 13:53:01 +0800
|
| Source diff to previous version |
| 2122382 |
[SRU] Improve audio profiles compatibility |
|
|
bluez (5.72-0ubuntu5.4) noble; urgency=medium
[ Andreas Glinserer ]
* d/patches: device-Fix-Pair-Method-not-setting-auto_connect.patch to fix
devices not setting autoconnect correctly. (LP: #2119741)
-- Daniel van Vugt <email address hidden> Mon, 11 Aug 2025 14:19:18 +0800
|
| Source diff to previous version |
| 2119741 |
Bluetooth device does not reconnect after being paired |
|
|
bluez (5.72-0ubuntu5.3) noble; urgency=medium
* d/patches: add reconnect-hsp-on-a2dp-reconnect.patch to fix HSP/HFP
connection after resuming from suspend on systems with NVIDIA proprietary
driver. (LP: #2092158)
-- Yao Wei (éÂ�éŠËå»·) <email address hidden> Thu, 10 Apr 2025 09:55:42 +0800
|
| 2092158 |
[SRU] With certain configs (such as with NVIDIA GPU driver), Bluetooth HSP/HFP profile may be missing after suspend/resume |
|
About
-
Send Feedback to @ubuntu_updates