{"id":"CVE-2026-101887","summary":"BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS","details":"BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.","modified":"2026-10-03T08:04:06.014350Z","published":"2026-10-01T02:28:18.194Z","database_specific":{"cwe_ids":["CWE-369"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101887.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1a84465dd860d1be9dcf62339c6273e9e0632dd2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101887.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101887"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/bluealsa-bluealsad-lc3plus-decoder-division-by-zero-dos"},{"type":"FIX","url":"https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2"},{"type":"PACKAGE","url":"https://github.com/arkq/bluez-alsa"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/arkq/bluez-alsa","events":[{"introduced":"0"},{"fixed":"1a84465dd860d1be9dcf62339c6273e9e0632dd2"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v5.0.0","v4.3.1","v4.3.0","v4.2.0","v4.1.1","v4.1.0","v4.0.0","v3.1.0","v3.0.0","v2.1.0","v2.0.0","v1.4.0","v1.3.1","v1.3.0","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101887.json","vanir_signatures_modified":"2026-10-03T08:04:06Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["264811917148832560564607037372657160539","127560339560363240969738235316008634190","140454364693443454457992172291290377767","202842260137274196180412169962022653020","333102183932242705187858821512468732242","181288002239720092837635410902307855711"],"threshold":0.9},"id":"CVE-2026-101887-1ee4b9b8","signature_type":"Line","signature_version":"v1","source":"https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2","target":{"file":"src/a2dp-lc3plus.c"}},{"deprecated":false,"digest":{"function_hash":"265008919369034180990673424063688042761","length":4500},"id":"CVE-2026-101887-f8fc6845","signature_type":"Function","signature_version":"v1","source":"https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2","target":{"file":"src/a2dp-lc3plus.c","function":"a2dp_lc3plus_dec_thread"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}