---
id: CVE-2026-101887
title: >-
  BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in
  the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows
  a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP
  media …
summary: >-
  BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in
  the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows
  a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP
  media …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-369
vendor: arkq
product: bluez-alsa
affected:
  - bluez-alsa < 1a84465dd860d1be9dcf62339c6273e9e0632dd2
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T03:16:58.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101887'
references:
  - url: >-
      https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/bluealsa-bluealsad-lc3plus-decoder-division-by-zero-dos
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T03:36:04.805Z'
---

## Overview

BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
