Out-of-bounds read in Linux kernel - CVE-2026-80759
Published: September 6, 2026
Vulnerability details
The vulnerability allows a local user to read beyond loaded firmware data.
The vulnerability exists due to an out-of-bounds read in the aml_download_firmware() function of the hci_aml Bluetooth driver when processing a truncated or inconsistent firmware image. A local user can provide a crafted firmware image to read beyond loaded firmware data.
Affected software
How to mitigate CVE-2026-80759
External References
- https://git.kernel.org/stable/c/2763b8bcb504e30ec955474f51b99ce42fc62f3b
- https://git.kernel.org/stable/c/2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4
- https://git.kernel.org/stable/c/6c70253462902d835e843b470f74aa816d60af80
- https://git.kernel.org/stable/c/7733b01ed13685773ccda91035a46f87d4cfef7c
- https://git.kernel.org/stable/c/e1534d49a7b8ba728e84b020f6d802aa1cb759d9