Skip to content
Red HatCVE-2026-16473

Red Hat sbc: out-of-bounds read

Medium4.3CVE-2026-16473 · Published Jul 22, 2026 · updated Jul 30, 2026

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat librest: attacker could bypass PKCE protections
Medium6.8Jul 22
Red Hat Directory Server 11: denial of service
Medium5.3Jul 22
Red Hat Ansible Automation Platform 2: command injection
High7.8Jul 22
Red Hat Ansible Automation Platform 2: path traversal
Medium6.6Jul 22
Red Hat Ansible Automation Platform 2: information disclosure
Low3.3Jul 22
Red Hat Ansible Automation Platform 2: command injection
High7.8Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.