CVE-2026-98110
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintel: bound firmware ID by TLV length
The firmware ID is treated as a NUL-terminated string even though the TLV length is its only boundary. If the value does not contain a NUL terminator, snprintf() can read beyond the received response.
Limit the conversion to the advertised TLV value length.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 164c62f958f8c7f0bde1e9a5a8677971c6f28205 < aef56a2bd5aa22808ce508605d7497d2b5e8eb5f | affected |
| Linux | Linux | 164c62f958f8c7f0bde1e9a5a8677971c6f28205 < 058f56de5f48ba4b3be01526006ac83ce9e79f39 | affected |
| Linux | Linux | 164c62f958f8c7f0bde1e9a5a8677971c6f28205 < a07b3024a927892dd46e7dfbed438e8834e24098 | affected |
| Linux | Linux | 164c62f958f8c7f0bde1e9a5a8677971c6f28205 < ac8aa9e0ec93a12a60230066f199f49c3b9aac3d | affected |
| Linux | Linux | 6.11 | affected |
| Linux | Linux | 0 < 6.11 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/aef56a2bd5aa22808ce508605d7497d2b5e8eb5f
- https://git.kernel.org/stable/c/058f56de5f48ba4b3be01526006ac83ce9e79f39
- https://git.kernel.org/stable/c/a07b3024a927892dd46e7dfbed438e8834e24098
- https://git.kernel.org/stable/c/ac8aa9e0ec93a12a60230066f199f49c3b9aac3d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.