Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93096.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93096
Upstream
  • CVE-2026-16473
Published
2026-07-22T11:16:50Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-16473 affecting package sbc 2.0-6
Details

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

References

Affected packages

Azure Linux:3 / sbc

Package

Name
sbc
Purl
pkg:rpm/azure-linux/sbc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93096.json"