CVE-2020-15710: Pulseaudio Project Pulseaudio
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
Affected products
- Pulseaudio Project Pulseaudio: version 1:8.0-0ubuntu1 only; version 1:8.0-0ubuntu2 only; version 1:8.0-0ubuntu3 only; version 1:8.0-0ubuntu3.1 only; version 1:8.0-0ubuntu3.2 only; version 1:8.0-0ubuntu3.3 only; …
Published 2020-11-19. Last modified 2026-06-17.