Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90251
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the kernel to read data beyond the controller response.
The vulnerability exists due to improper validation of an event prefix length in the Bluetooth MSFT read_supported_features() handler when handling an MSFT read supported features response from a Bluetooth controller. A remote attacker can provide a response whose declared event-prefix length exceeds its actual length to cause the kernel to read data beyond the controller response.
The copied data is later used to match incoming vendor events.
Affected software
How to mitigate CVE-2026-90251
External References
- https://git.kernel.org/stable/c/0079e1a944634ab2dc1c7cdec1144486d096407e
- https://git.kernel.org/stable/c/21f539c59ed330b671d75fd119c5f659ff92fbd1
- https://git.kernel.org/stable/c/52b1b3b4d403cbda1b70ce2385e1a71f166a87ba
- https://git.kernel.org/stable/c/620c2631cff490d14d0b9d56f185cc745806d6d7
- https://git.kernel.org/stable/c/63562cfaea8a650fdb31ee8de21c32e3600be642
- https://git.kernel.org/stable/c/7c2658023d839b651368a5b8b781bf9a817647cb
- https://git.kernel.org/stable/c/dce783a10e70f013410f5b583a29fc3286899629
- https://git.kernel.org/stable/c/e804d54a5a99d99250490e68093eff7190472e6f