Bluetooth: HIDP: validate numbered report payloads
Summary
| CVE | CVE-2026-74507 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:55 UTC |
| Updated | 2026-08-15 13:17:55 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: HIDP: validate numbered report payloads
When hidp_get_raw_report() waits for a numbered report,
hidp_process_data() compares the expected report number with skb->data[0].
A connected HIDP peer can reply with only a DATA transaction header,
leaving the skb empty after the header is removed.
KMSAN reports an uninitialized-value use in hidp_session_run(), with the
value originating in __alloc_skb() through vhci_write(). The transaction
header checks remove the empty-frame reports, but this report remains until
the payload check is added.
The comparison can also consume a peer-controlled byte beyond the declared
L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made
the current code accept that byte as report ID 1 and complete
HIDIOCGFEATURE with a zero-byte result. With this change the malformed
response is rejected with -EIO, while a subsequent valid response still
succeeds.
Require a payload byte before comparing a numbered report ID. Unnumbered
reports continue to accept an empty payload. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 0ff1731a1ae51e8e48cd559d70db536281c47f8e b7ad105d46acd828e424454815e4cd31069e047a git |
Not specified |
| CNA |
Linux |
Linux |
affected 0ff1731a1ae51e8e48cd559d70db536281c47f8e 7e7162427659b70ea17cd41b1f79e2e64c246690 git |
Not specified |
| CNA |
Linux |
Linux |
affected 0ff1731a1ae51e8e48cd559d70db536281c47f8e 27cc0e603355c585f1e5da8398faa4d36d498188 git |
Not specified |
| CNA |
Linux |
Linux |
affected 0ff1731a1ae51e8e48cd559d70db536281c47f8e 9c841f59e10b5d75c398a3fc6b2da448d2a2276b git |
Not specified |
| CNA |
Linux |
Linux |
affected 0ff1731a1ae51e8e48cd559d70db536281c47f8e 34f53d27b81a16a02828c8fdfa4e02badc326f17 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.39 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.39 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.151 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.