SB20260918416 - Improper Validation of Specified Quantity in Input in Linux kernel bluetooth
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-90251)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the kernel to read data beyond the controller response.
The vulnerability exists due to improper validation of an event prefix length in the Bluetooth MSFT read_supported_features() handler when handling an MSFT read supported features response from a Bluetooth controller. A remote attacker can provide a response whose declared event-prefix length exceeds its actual length to cause the kernel to read data beyond the controller response.
The copied data is later used to match incoming vendor events.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0079e1a944634ab2dc1c7cdec1144486d096407e
- https://git.kernel.org/stable/c/21f539c59ed330b671d75fd119c5f659ff92fbd1
- https://git.kernel.org/stable/c/52b1b3b4d403cbda1b70ce2385e1a71f166a87ba
- https://git.kernel.org/stable/c/620c2631cff490d14d0b9d56f185cc745806d6d7
- https://git.kernel.org/stable/c/63562cfaea8a650fdb31ee8de21c32e3600be642
- https://git.kernel.org/stable/c/7c2658023d839b651368a5b8b781bf9a817647cb
- https://git.kernel.org/stable/c/dce783a10e70f013410f5b583a29fc3286899629
- https://git.kernel.org/stable/c/e804d54a5a99d99250490e68093eff7190472e6f