Answer in brief
CVE-2026-101887 records a Low severity (CVSS 2.1) vulnerability in BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS. The current sources do not mark it as known exploited. The current feed maps arkq/bluez-alsa (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 2.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps arkq/bluez-alsa (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| arkq/bluez-alsageneric | >=0 <1a84465dd860d1be9dcf62339c6273e9e0632dd2 | 1a84465dd860d1be9dcf62339c6273e9e0632dd2 |
Published upstream
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 1, 2026
BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.
Quoted source text, attributed separately from HOL analysis.