8.8

CVE-2026-74508

Bluetooth: HIDP: reject frames without a transaction header

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: HIDP: reject frames without a transaction header

hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0]
before checking that the L2CAP SDU contains a transaction header. A
connected HIDP peer can send an empty basic-mode SDU and make both paths
use an uninitialized byte from skb tailroom.

KMSAN reports the use in hidp_session_run(), with the uninitialized value
originating in __alloc_skb() through vhci_write(). The control path
produces two reports and the interrupt path produces one.

The byte can also be controlled by a malformed lower-layer packet. If an
HCI ACL packet contains an L2CAP PDU with a declared zero-length payload
followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to
the declared PDU length before dispatch. The current HIDP path nevertheless
consumes the extra byte as HIDP_TRANS_HID_CONTROL |
HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this
change, the same packet is discarded and a subsequent feature report
request succeeds.

Pull the transaction header with skb_pull_data() and discard frames that
do not contain it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 238c333bc4b3f245c626632e8bfa3c9dab97f51b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 567a2a0a633f2ea5fdccaf3517c09f22c9d860c7
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 97b61241ab45bfa5b0526cb0f3978942493bc811
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 2ebf63aa557a69990b4e9ea22be224d58aabce96
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 854194494a6f726a60b90b76059148bf08df023d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 47778d2c2087b5d192398f6fddf692d16a5431cf
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.175
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec
https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811
https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96
https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d
https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf
https://git.kernel.org/stable/c/238c333bc4b3f245c626632e8bfa3c9dab97f51b
https://git.kernel.org/stable/c/567a2a0a633f2ea5fdccaf3517c09f22c9d860c7
https://git.kernel.org/stable/c/24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8