-

CVE-2026-64549

Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()

bpa10x_setup() sends the vendor command 0xfc0e and passes the response
to bt_dev_info() and hci_set_fw_info() as a "%s" string starting at
skb->data + 1, without checking the length:

	bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
	hci_set_fw_info(hdev, "%s", skb->data + 1);

A device that returns a one-byte response (status only) leaves
skb->data + 1 past the end of the data, and the %s walk reads adjacent
slab memory until it meets a NUL. The same happens when the payload is
not NUL-terminated within skb->len. The out-of-bounds bytes end up in
the kernel log and the firmware-info debugfs file.

Print the revision string with a bounded "%.*s" limited to skb->len - 1
instead. This keeps the string readable for well-behaved devices while
never reading past the received data, and does not fail setup, so a
device returning a short or unterminated response keeps working.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < 1813add71e386f77b3040e6c8dc9b7b3ff965a6c
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < bd56c23f1f8681a2857ee924a8bd3abf87c8913b
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < 7a64f39ebe1bacd9004a62eceadac0b122ec3cc2
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < f80b4afe893dffa9fabdbf80fb4d6782b24a6793
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < 4b4008dda1d0c6e598d7865631ad4eda63a560f0
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < bfc9e7be289df11e8e38c98cd78019d67fdd0bd5
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < a8e169d308775039200bb9c905c7ce420db6e8c5
Status affected
Version ddd68ec8f4847b460c9f580076eafe13b031a6fd
Version < dd068ef044128db655f48323a4acfd5907e04903
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.4
Status affected
Version 0
Version < 4.4
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1813add71e386f77b3040e6c8dc9b7b3ff965a6c
https://git.kernel.org/stable/c/bd56c23f1f8681a2857ee924a8bd3abf87c8913b
https://git.kernel.org/stable/c/7a64f39ebe1bacd9004a62eceadac0b122ec3cc2
https://git.kernel.org/stable/c/f80b4afe893dffa9fabdbf80fb4d6782b24a6793
https://git.kernel.org/stable/c/4b4008dda1d0c6e598d7865631ad4eda63a560f0
https://git.kernel.org/stable/c/bfc9e7be289df11e8e38c98cd78019d67fdd0bd5
https://git.kernel.org/stable/c/a8e169d308775039200bb9c905c7ce420db6e8c5
https://git.kernel.org/stable/c/dd068ef044128db655f48323a4acfd5907e04903