7.1
CVE-2026-90089
- EPSS 0.29%
- Veröffentlicht 17.09.2026 16:06:04
- Zuletzt bearbeitet 18.09.2026 18:17:41
- Erkennungen
Bluetooth: btnxpuart: Validate the FW dump header length
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Validate the FW dump header length nxp_process_fw_dump() pulls the ACL header off the frame and then reads seq_num and buf_len from a struct nxp_fw_dump_hdr placed at skb->data, without checking that the ACL payload is long enough to contain it. h4_recv_buf() collects HCI_ACL_HDR_SIZE bytes of header followed by the number of payload bytes named in that header, so skb->len is 4 + dlen with dlen supplied by the controller and possibly smaller than the 8 byte dump header, or zero. A short frame with connection handle 0xfff therefore reads both fields from beyond the received data. Beyond the read itself, buf_len is what terminates a dump: a value of zero makes the driver call hci_devcd_complete() and reset the controller, so a truncated frame can end a dump early. Use skb_pull_data() to validate and pull the FW dump header before accessing its fields. Warn and reject the chunk if the header is truncated.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
998e447f443f138c90faa6ff3845082af419070e
Version <
a644b8df94966b672ac656577df98bd01bc88393
Status
affected
Version
998e447f443f138c90faa6ff3845082af419070e
Version <
22d419db7f9a01bea22cfcf66774d2b2fd4bb354
Status
affected
Version
998e447f443f138c90faa6ff3845082af419070e
Version <
060fa7592bdc043a93b6b7870f5b8551206d315d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.217 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
|
https://git.kernel.org/stable/c/a644b8df94966b672ac656577df98bd01bc88393
https://git.kernel.org/stable/c/22d419db7f9a01bea22cfcf66774d2b2fd4bb354
https://git.kernel.org/stable/c/060fa7592bdc043a93b6b7870f5b8551206d315d