8.8

CVE-2026-72334

Bluetooth: ISO: fix malformed ISO_END/CONT handling

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: fix malformed ISO_END/CONT handling

Core specification (Part C vol 4 sec 5.4.5) does not exclude empty
ISO_CONT, ISO_END packets.  We currently reject them if they are last.

If controller sends malformed sequence

    ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START

that ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends
too long ISO_END, we panic on skb_put. If controller sends too short
ISO_END we accept it.

Fix by marking unfinished ISO_START via conn->rx_skb != NULL.  Check
skb->len properly before skb_put.  Combine the ISO_CONT/END code paths
as they require the same initial checks. Reject too short ISO_END
packets.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < d2df29dc9abda2fc10ff522eac0969f5b77b3637
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 7250b6b5ba9b737cff2c2c1d0760360c7b6bca00
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 49aeb54e3c912ef785311264a51ab9f3698e421b
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 5e53e285f8c989662e34d4938c728a94226bff34
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < 990e65eb9387c4ddfa7f68782b6644c2c35d489f
Status affected
Version ccf74f2390d60a2f9a75ef496d2564abb478f46a
Version < e054c1a6ae7310d2815778fddb87da616e11c255
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.271
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/990e65eb9387c4ddfa7f68782b6644c2c35d489f
https://git.kernel.org/stable/c/e054c1a6ae7310d2815778fddb87da616e11c255
https://git.kernel.org/stable/c/49aeb54e3c912ef785311264a51ab9f3698e421b
https://git.kernel.org/stable/c/5e53e285f8c989662e34d4938c728a94226bff34
https://git.kernel.org/stable/c/7250b6b5ba9b737cff2c2c1d0760360c7b6bca00
https://git.kernel.org/stable/c/d2df29dc9abda2fc10ff522eac0969f5b77b3637