Bluetooth: qca: fix NVM tag length underflow in TLV parser

Summary

CVECVE-2026-64573
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-05 08:16:37 UTC
Updated2026-08-05 08:16:37 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV parser In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is "while (idx < length - sizeof(struct tlv_type_nvm))". "length" is a signed int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a size_t (12), so "length" is converted to size_t and any firmware-supplied "length" < 12 makes the subtraction wrap to a huge value. The loop body then reads a 12-byte struct tlv_type_nvm past the end of the short vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it). Rewrite the bound as "idx + sizeof(struct tlv_type_nvm) <= length"; both operands are non-negative, so it no longer underflows and a "length" too small for one record correctly skips the loop. BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421) Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52 Workqueue: hci0 hci_power_on Call Trace: ... kasan_report (mm/kasan/report.c:595) qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617) qca_uart_setup (drivers/bluetooth/btqca.c:948) qca_setup (drivers/bluetooth/hci_qca.c:2029) hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438) hci_dev_open_sync (net/bluetooth/hci_sync.c:5227) hci_power_on (net/bluetooth/hci_core.c:920) process_one_work (kernel/workqueue.c:3322) worker_thread (kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 427281f9498ed614f9aabc80e46ec077c487da6d 70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24 git Not specified
CNA Linux Linux affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d 59fd2f075bca94f030c7c78e94878ea0803d7690 git Not specified
CNA Linux Linux affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d a087ed960fce54e9302796229e9d545bbc9bcd4a git Not specified
CNA Linux Linux affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d 4fcfb5b2c736785464ff9745f94c6726c5ee2d85 git Not specified
CNA Linux Linux affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d c90164ca0f7036942ba088eb7ea8d3f6c2352020 git Not specified
CNA Linux Linux affected ed53949cc92e28aaa3463d246942bda1fbb7f307 git Not specified
CNA Linux Linux affected 1caceadfb50432dbf6d808796cb6c34ebb6d662c git Not specified
CNA Linux Linux affected 02f05ed44b71152d5e11d29be28aed91c0489b4e git Not specified
CNA Linux Linux affected 6.6.31 6.6.148 semver Not specified
CNA Linux Linux affected 5.15.159 5.16 semver Not specified
CNA Linux Linux affected 6.1.91 6.2 semver Not specified
CNA Linux Linux affected 6.8.10 6.9 semver Not specified
CNA Linux Linux affected 6.9 Not specified
CNA Linux Linux unaffected 6.9 semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.42 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.6 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report