-
CVE-2026-98110
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:35:58
- Zuletzt bearbeitet 30.09.2026 14:10:59
- Erkennungen
Bluetooth: btintel: bound firmware ID by TLV length
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: bound firmware ID by TLV length The firmware ID is treated as a NUL-terminated string even though the TLV length is its only boundary. If the value does not contain a NUL terminator, snprintf() can read beyond the received response. Limit the conversion to the advertised TLV value length.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
164c62f958f8c7f0bde1e9a5a8677971c6f28205
Version <
aef56a2bd5aa22808ce508605d7497d2b5e8eb5f
Status
affected
Version
164c62f958f8c7f0bde1e9a5a8677971c6f28205
Version <
058f56de5f48ba4b3be01526006ac83ce9e79f39
Status
affected
Version
164c62f958f8c7f0bde1e9a5a8677971c6f28205
Version <
a07b3024a927892dd46e7dfbed438e8834e24098
Status
affected
Version
164c62f958f8c7f0bde1e9a5a8677971c6f28205
Version <
ac8aa9e0ec93a12a60230066f199f49c3b9aac3d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.11
Status
affected
Version
0
Version <
6.11
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/aef56a2bd5aa22808ce508605d7497d2b5e8eb5f
https://git.kernel.org/stable/c/058f56de5f48ba4b3be01526006ac83ce9e79f39
https://git.kernel.org/stable/c/a07b3024a927892dd46e7dfbed438e8834e24098
https://git.kernel.org/stable/c/ac8aa9e0ec93a12a60230066f199f49c3b9aac3d