SB20260918416 - Improper Validation of Specified Quantity in Input in Linux kernel bluetooth



SB20260918416 - Improper Validation of Specified Quantity in Input in Linux kernel bluetooth

Published: September 18, 2026

Security Bulletin ID SB20260918416
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-90251)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the kernel to read data beyond the controller response.

The vulnerability exists due to improper validation of an event prefix length in the Bluetooth MSFT read_supported_features() handler when handling an MSFT read supported features response from a Bluetooth controller. A remote attacker can provide a response whose declared event-prefix length exceeds its actual length to cause the kernel to read data beyond the controller response.

The copied data is later used to match incoming vendor events.


Remediation

Install update from vendor's website.