Out-of-bounds read in Linux kernel - CVE-2026-98110
Published: September 28, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause an out-of-bounds read.
The vulnerability exists due to treating a length-bounded value as a NUL-terminated string in btintel firmware ID TLV parsing when processing a received firmware ID TLV without a NUL terminator. An attacker with physical access can provide a firmware ID TLV lacking a NUL terminator to cause an out-of-bounds read.