-

CVE-2026-80760

Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255

mgmt_hci_cmd_sync() checks that the message length agrees with params_len
but puts no upper bound on it. params_len is __le16 while the parameter
length in the HCI command header is a u8:

	struct hci_command_hdr {
		__le16	opcode;
		__u8	plen;
	} __packed;

hci_cmd_sync_alloc() assigns one to the other:

	hdr->plen = plen;

	if (plen)
		skb_put_data(skb, param, plen);

so a params_len of 256 leaves plen at 0 while all 256 bytes are still
appended. The frame handed to the driver then declares no parameters and
carries 256 of them. On a length framed transport such as H:4 the
controller takes the trailing bytes as the start of the next packet.

The mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params_len can reach about
1KB this way. Commit 03f1700b9b4d ("Bluetooth: MGMT: reject malformed
HCI_CMD_SYNC commands") only made params_len agree with the message
length, a value that fits the message but not the header field is still
accepted.

Reject params_len that does not fit the header field.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 827af4787e74e8df9e8e0677a69fbb15e0856d2f
Version < b7d9edcf9fe6e9ec3a2e80ef9e8d44ef9b4f2894
Status affected
Version 827af4787e74e8df9e8e0677a69fbb15e0856d2f
Version < 0bd0195ce25737cbdd0eabc54319ee0ddf3a0ad2
Status affected
Version 827af4787e74e8df9e8e0677a69fbb15e0856d2f
Version < 6e1c44878aa3ee7336efeaf01414b030b0a5c273
Status affected
Version 827af4787e74e8df9e8e0677a69fbb15e0856d2f
Version < 5d95286b6d6e8f1d304da7522bfa6860fc017e48
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.13
Status affected
Version 0
Version < 6.13
Status unaffected
Version <= 6.18.*
Version 6.18.47
Status unaffected
Version <= 7.1.*
Version 7.1.11
Status unaffected
Version <= 7.2.*
Version 7.2.1
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b7d9edcf9fe6e9ec3a2e80ef9e8d44ef9b4f2894
https://git.kernel.org/stable/c/0bd0195ce25737cbdd0eabc54319ee0ddf3a0ad2
https://git.kernel.org/stable/c/6e1c44878aa3ee7336efeaf01414b030b0a5c273
https://git.kernel.org/stable/c/5d95286b6d6e8f1d304da7522bfa6860fc017e48