Out-of-bounds read in Linux kernel - CVE-2026-90257
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in virtbt_setup_zephyr() when processing a status-only Read Build Information response from a Bluetooth virtio backend. A local user can provide a response containing only a status byte to disclose sensitive information.
Adjacent slab memory bytes may be exposed through the kernel log and the firmware-info debugfs file.
Affected software
How to mitigate CVE-2026-90257
External References
- https://git.kernel.org/stable/c/0e388d805233a883a31271676eae6031dfc9e898
- https://git.kernel.org/stable/c/502adc06ba76dee19c292ae4a07d74d202fe734d
- https://git.kernel.org/stable/c/54e9387eb7546eaa6f600220599d55740956ffc3
- https://git.kernel.org/stable/c/84ea9c99874804f5ca13f35bbc186ba93902f30f
- https://git.kernel.org/stable/c/be1e3df2c49c91b0a052c6563884e8d39bd768b2
- https://git.kernel.org/stable/c/d08c99abf06133a7829d46627e77e3315ca974d2
- https://git.kernel.org/stable/c/fb445b3466a8d1c7a0b0d0676fb475e3ce22d94e