Out-of-bounds read in Linux kernel - CVE-2026-64407

 

Out-of-bounds read in Linux kernel - CVE-2026-64407

Published: July 27, 2026


Vulnerability identifier: #VU139561
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64407
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in nxp_recv_fw_req_v3() in the btnxpuart Bluetooth driver when processing v3 firmware download requests from the controller. A local user can supply a controller that requests an offset or length beyond the firmware image to disclose sensitive information.

The issue occurs during firmware download over UART.


Affected software

Linux kernel

How to mitigate CVE-2026-64407

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins