Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90251

 

Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90251

Published: September 18, 2026


Vulnerability identifier: #VU151229
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90251
CWE-ID: CWE-1284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the kernel to read data beyond the controller response.

The vulnerability exists due to improper validation of an event prefix length in the Bluetooth MSFT read_supported_features() handler when handling an MSFT read supported features response from a Bluetooth controller. A remote attacker can provide a response whose declared event-prefix length exceeds its actual length to cause the kernel to read data beyond the controller response.

The copied data is later used to match incoming vendor events.


Affected software

Linux kernel

How to mitigate CVE-2026-90251

Install security update from vendor's repository.


External References

Related Security Bulletins