USN-8908-1: Five BlueZ flaws, risk of code execution on Ubuntu
Canonical has released patched versions of bluez for six Ubuntu releases following five CVEs, two of which carry a risk of stack buffer overflow.
UptimeMag editorial team · 9 October 2026 · 1 min read

On 8 October 2026, Canonical published advisory USN-8908-1, which fixes five vulnerabilities in the bluez package, the Bluetooth stack used on Ubuntu. This affects anyone managing machines with Bluetooth enabled: workstations, edge devices, IoT boxes. On a headless server with no Bluetooth stack loaded, the practical impact is limited, but it's still worth checking what's running.\n\n## The flaws\n\nMichael Bommarito discovered that BlueZ incorrectly handled the storage of codec capabilities in the A2DP profile. An attacker could exploit this issue to cause a stack buffer overflow, resulting in denial of service or arbitrary code execution. The issue affects only Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS (CVE-2026-19774).
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50).