7.8

CVE-2026-64539

Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies
the per-instance data without checking that it still fits:

	memcpy(ptr, adv->adv_data, adv->adv_data_len);

tlv_data_max_len() only reserves those 3 bytes when the user-supplied
flags carry a managed-flags bit, so an instance added with flags == 0 is
accepted with adv_data_len up to the full buffer. At advertise time the
flags are still prepended, and the memcpy() writes 3 + adv_data_len
bytes into the size-byte buffer:

  BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301)
  Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65
  Workqueue: hci0 hci_cmd_sync_work
   __asan_memcpy (mm/kasan/shadow.c:106)
   eir_create_adv_data (net/bluetooth/eir.c:301)
   hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310)
   hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817)
   hci_cmd_sync_work (net/bluetooth/hci_sync.c:332)
  This frame has 1 object:
   [32, 64) 'cp'

The "Flags" structure is added by the kernel, not requested by
userspace, so only prepend it when it fits together with the instance
advertising data; when there is no room for both, drop the flags rather
than the user-provided data.

Reachable by a local user with CAP_NET_ADMIN owning an LE-only
controller on the legacy advertising path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version b44133ff03be30b55f23036e62f403a3f7784fce
Version < 0f0b6232af56441d0a2dcb173cc4f8d8aab39014
Status affected
Version b44133ff03be30b55f23036e62f403a3f7784fce
Version < 09301f1fdf2aef8cce34d0c4650c30e7edb1ced9
Status affected
Version b44133ff03be30b55f23036e62f403a3f7784fce
Version < f1b4df9c260c51726da2e86e19322825fddeefd0
Status affected
Version b44133ff03be30b55f23036e62f403a3f7784fce
Version < 57077eeb586c42f124bc09e018449362223067b3
Status affected
Version b44133ff03be30b55f23036e62f403a3f7784fce
Version < 6f5fb689fdf80bdd143f22a502f9eb1f3c85e286
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.1
Status affected
Version 0
Version < 4.1
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0f0b6232af56441d0a2dcb173cc4f8d8aab39014
https://git.kernel.org/stable/c/09301f1fdf2aef8cce34d0c4650c30e7edb1ced9
https://git.kernel.org/stable/c/f1b4df9c260c51726da2e86e19322825fddeefd0
https://git.kernel.org/stable/c/57077eeb586c42f124bc09e018449362223067b3
https://git.kernel.org/stable/c/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286