-
CVE-2026-97907
- EPSS 0.2%
- Veröffentlicht 25.09.2026 10:22:32
- Zuletzt bearbeitet 03.10.2026 11:18:09
- Erkennungen
Bluetooth: btrtl: Don't leak return code when parsing firmware format v2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 When key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally ignores all security headers. However, the implementation simply breaks from a switch statement and leaks uninitialized return code `rc' (if the first section is a security one) or the previous section's `rc'. Fix it by really skipping a loop with `continue'. For consistency and readability, also do the same for the default case.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa
Version <
ba96047bba4a6101267cf4f6b3057cbc58e6c554
Status
affected
Version
9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa
Version <
90f3a142b5f8596a565b8e080d18a8050be6edef
Status
affected
Version
9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa
Version <
422f6547259654bae690713614c794dd1e2c0a0b
Status
affected
Version
9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa
Version <
c4249cf6e80b1bd62a6a409aaabe760fe025dac3
Status
affected
Version
9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa
Version <
83e3e515fd261600ed8491fb0a8bcdfb115c904e
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.4
Status
affected
Version
0
Version <
6.4
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.088 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/90f3a142b5f8596a565b8e080d18a8050be6edef
https://git.kernel.org/stable/c/422f6547259654bae690713614c794dd1e2c0a0b
https://git.kernel.org/stable/c/c4249cf6e80b1bd62a6a409aaabe760fe025dac3
https://git.kernel.org/stable/c/83e3e515fd261600ed8491fb0a8bcdfb115c904e
https://git.kernel.org/stable/c/ba96047bba4a6101267cf4f6b3057cbc58e6c554