8.8
CVE-2026-74508
- EPSS 0.26%
- Veröffentlicht 15.08.2026 12:27:31
- Zuletzt bearbeitet 23.08.2026 13:16:44
- CVE-Watchlists
- Unerledigt
Bluetooth: HIDP: reject frames without a transaction header
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transaction header hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0] before checking that the L2CAP SDU contains a transaction header. A connected HIDP peer can send an empty basic-mode SDU and make both paths use an uninitialized byte from skb tailroom. KMSAN reports the use in hidp_session_run(), with the uninitialized value originating in __alloc_skb() through vhci_write(). The control path produces two reports and the interrupt path produces one. The byte can also be controlled by a malformed lower-layer packet. If an HCI ACL packet contains an L2CAP PDU with a declared zero-length payload followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to the declared PDU length before dispatch. The current HIDP path nevertheless consumes the extra byte as HIDP_TRANS_HID_CONTROL | HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this change, the same packet is discarded and a subsequent feature report request succeeds. Pull the transaction header with skb_pull_data() and discard frames that do not contain it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
238c333bc4b3f245c626632e8bfa3c9dab97f51b
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
567a2a0a633f2ea5fdccaf3517c09f22c9d860c7
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
97b61241ab45bfa5b0526cb0f3978942493bc811
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
2ebf63aa557a69990b4e9ea22be224d58aabce96
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
854194494a6f726a60b90b76059148bf08df023d
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
47778d2c2087b5d192398f6fddf692d16a5431cf
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.266
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.151
Status
unaffected
Version <=
6.12.*
Version
6.12.103
Status
unaffected
Version <=
6.18.*
Version
6.18.44
Status
unaffected
Version <=
7.1.*
Version
7.1.8
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec
https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811
https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96
https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d
https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf
https://git.kernel.org/stable/c/238c333bc4b3f245c626632e8bfa3c9dab97f51b
https://git.kernel.org/stable/c/567a2a0a633f2ea5fdccaf3517c09f22c9d860c7
https://git.kernel.org/stable/c/24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8