-

CVE-2026-90257

Bluetooth: virtio_bt: avoid OOB read of build info string

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: virtio_bt: avoid OOB read of build info string

The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read
Build Information) and hands the response to bt_dev_info() and
hci_set_fw_info() as a "%s" string starting at skb->data + 1, without
checking the length. A backend that answers with status only leaves that
pointer past the end of the received data, so the walk reads adjacent
slab memory until it meets a NUL. Those bytes reach the kernel log and
the firmware-info debugfs file.

To fix this, print the string with a bounded "%.*s" limited to
skb->len - 1. A short or unterminated response then prints as much as
arrived instead of failing setup.

This mirrors commit dd068ef04412 ("Bluetooth: bpa10x: avoid OOB read of
revision string in bpa10x_setup()"), which fixed the identical pattern.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < fb445b3466a8d1c7a0b0d0676fb475e3ce22d94e
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < d08c99abf06133a7829d46627e77e3315ca974d2
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < 0e388d805233a883a31271676eae6031dfc9e898
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < 54e9387eb7546eaa6f600220599d55740956ffc3
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < be1e3df2c49c91b0a052c6563884e8d39bd768b2
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < 84ea9c99874804f5ca13f35bbc186ba93902f30f
Status affected
Version afd2daa26c7abd734d78bd274fc6c59a15e61063
Version < 502adc06ba76dee19c292ae4a07d74d202fe734d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fb445b3466a8d1c7a0b0d0676fb475e3ce22d94e
https://git.kernel.org/stable/c/d08c99abf06133a7829d46627e77e3315ca974d2
https://git.kernel.org/stable/c/0e388d805233a883a31271676eae6031dfc9e898
https://git.kernel.org/stable/c/54e9387eb7546eaa6f600220599d55740956ffc3
https://git.kernel.org/stable/c/be1e3df2c49c91b0a052c6563884e8d39bd768b2
https://git.kernel.org/stable/c/84ea9c99874804f5ca13f35bbc186ba93902f30f
https://git.kernel.org/stable/c/502adc06ba76dee19c292ae4a07d74d202fe734d