CVE-2023-51592
NixOS vulnerability analysis and mitigation

Overview

BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2023-51592) affects BlueZ installations. This vulnerability was discovered and reported by Lucas Leong of Trend Micro Zero Day Initiative. The issue was disclosed on December 21, 2023, and allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected BlueZ installations (Zero Day Initiative).

Technical details

The vulnerability exists within the handling of the AVRCP protocol in BlueZ. The specific flaw results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. The vulnerability has been assigned a CVSS v3 base score of 5.4 (Moderate) with the vector string CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L. The weakness is classified as CWE-125 (Out-of-bounds Read) (Zero Day Initiative, Red Hat).

Impact

The vulnerability can lead to the disclosure of sensitive information through Bluetooth connections. An attacker can leverage this vulnerability in conjunction with other vulnerabilities to execute arbitrary code in the context of root. The out-of-bounds read could potentially expose memory contents, including sensitive data such as cryptographic keys, PII, or memory addresses that could be used in additional attacks (Zero Day Initiative).

Exploitability

This vulnerability requires network-adjacent access and user interaction for exploitation. Specifically, the target must connect to a malicious device for the attack to be successful. The attack complexity is considered high, requiring no privileges but demanding user interaction (Zero Day Initiative).

Mitigation and workarounds

Given the nature of the vulnerability, the primary mitigation strategy is to restrict interaction with the application. Updates have been released by vendors such as Red Hat to address this vulnerability in their supported versions (Red Hat).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management