BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-369"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101887.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1a84465dd860d1be9dcf62339c6273e9e0632dd2"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101887.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"264811917148832560564607037372657160539",
"127560339560363240969738235316008634190",
"140454364693443454457992172291290377767",
"202842260137274196180412169962022653020",
"333102183932242705187858821512468732242",
"181288002239720092837635410902307855711"
],
"threshold": 0.9
},
"id": "CVE-2026-101887-1ee4b9b8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2",
"target": {
"file": "src/a2dp-lc3plus.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "265008919369034180990673424063688042761",
"length": 4500
},
"id": "CVE-2026-101887-f8fc6845",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2",
"target": {
"file": "src/a2dp-lc3plus.c",
"function": "a2dp_lc3plus_dec_thread"
}
}
]
"2026-10-02T08:13:50Z"