* CVE-2026-64126: Bluetooth: MGMT: validate Add Extended Advertising Data length
@ 2026-07-19 15:39 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-07-19 15:39 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: validate Add Extended Advertising Data length
MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command,
with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. The handler
then uses cp->adv_data_len and cp->scan_rsp_len to validate and copy
cp->data, but it never checks that those bytes are part of the mgmt
command payload.
A short command can therefore make add_ext_adv_data() pass an
out-of-bounds pointer into tlv_data_is_valid(). If the bytes beyond
the command buffer are addressable, they can also be copied into the
advertising instance as scan response data, where the caller can read
them back via MGMT_OP_GET_ADV_INSTANCE. The trigger requires
CAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte
slab-out-of-bounds read.
Reject commands whose length does not match the fixed header plus both
advertising data lengths before parsing cp->data.
The Linux kernel CVE team has assigned CVE-2026-64126 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 5.15.210 with commit 0d5104390b445e7bd664ad583837e4c04d892c9d
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 6.1.175 with commit 14b01b9cba04e6ce82825f68fc4c4322fa4ffa43
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 6.6.142 with commit a143ce77a5292f2c9285137433d879ce71d190a7
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 6.12.92 with commit a6c75a3fad226ccbd8ef9110dee87c92c299f2ab
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 6.18.34 with commit f1febe93ef075314615f970a87681d9ab86691d1
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 7.0.11 with commit 0bc1a5a69f541859293d79db72bd7854ac48df51
Issue introduced in 5.11 with commit 12410572833a283ce92fcf9679ca8a2f372097ee and fixed in 7.1 with commit d3f7d17960ed50df3a6709c5158caff989c8c905
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-64126
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/bluetooth/mgmt.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/0d5104390b445e7bd664ad583837e4c04d892c9d
https://git.kernel.org/stable/c/14b01b9cba04e6ce82825f68fc4c4322fa4ffa43
https://git.kernel.org/stable/c/a143ce77a5292f2c9285137433d879ce71d190a7
https://git.kernel.org/stable/c/a6c75a3fad226ccbd8ef9110dee87c92c299f2ab
https://git.kernel.org/stable/c/f1febe93ef075314615f970a87681d9ab86691d1
https://git.kernel.org/stable/c/0bc1a5a69f541859293d79db72bd7854ac48df51
https://git.kernel.org/stable/c/d3f7d17960ed50df3a6709c5158caff989c8c905
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-07-19 15:46 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-19 15:39 CVE-2026-64126: Bluetooth: MGMT: validate Add Extended Advertising Data length Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.