Out-of-bounds read in Linux kernel - CVE-2026-46186
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in virtbt_rx_handle() and Bluetooth HCI packet classification when processing a backend-supplied RX packet with an insufficient header length. A local user can provide a specially crafted RX completion with a truncated packet to disclose sensitive information.
The issue can be triggered when the virtio Bluetooth device has an active CIS_LINK, BIS_LINK, or PA_LINK connection.
How to mitigate CVE-2026-46186
Sources
- https://git.kernel.org/stable/c/1e1e509b6fd2a42421745bbcd98bd16daad20904
- https://git.kernel.org/stable/c/2c1143564c71e7497b42d8360a8379ccbb011d3c
- https://git.kernel.org/stable/c/3485c7236c59c8c34a41af1c4b52982437554e79
- https://git.kernel.org/stable/c/daf23014e5d975e72ea9c02b5160d3fcf070ea47
- https://git.kernel.org/stable/c/f743eab6486965f276c7e3f1700895f014fdc6db