Bluetooth: btintel: Validate length before parsing diagnostics TLV
Summary
| CVE | CVE-2026-74532 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:58 UTC |
| Updated | 2026-08-17 06:19:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate length before parsing diagnostics TLV btintel_diagnostics() accesses tlv->val[0] without first validating that the diagnostics VSE is long enough to contain that field, so may cause reading data beyond the received frame. Fix by validating the length before access. |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.064890000 (date 2026-08-16)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected af395330abed142a2685bf3d17a938544816bf3c c31be902ccbbb0b2c23159a1481dce80d1f9753d git | Not specified |
| CNA | Linux | Linux | affected af395330abed142a2685bf3d17a938544816bf3c dd20e30bdbd707ea8ced581f3d7f9e9854634b17 git | Not specified |
| CNA | Linux | Linux | affected af395330abed142a2685bf3d17a938544816bf3c c618a9a5b08ea2e17bddf4e948be9f75d408fca4 git | Not specified |
| CNA | Linux | Linux | affected af395330abed142a2685bf3d17a938544816bf3c 6ec9c3dc52302b891513f608f5fb478349b15ab3 git | Not specified |
| CNA | Linux | Linux | affected af395330abed142a2685bf3d17a938544816bf3c b640ff9af3c809ff5ea2077fbba17df1594ec1e4 git | Not specified |
| CNA | Linux | Linux | affected 6.4 | Not specified |
| CNA | Linux | Linux | unaffected 6.4 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.103 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.44 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.8 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c31be902ccbbb0b2c23159a1481dce80d1f9753d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c618a9a5b08ea2e17bddf4e948be9f75d408fca4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/dd20e30bdbd707ea8ced581f3d7f9e9854634b17 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b640ff9af3c809ff5ea2077fbba17df1594ec1e4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6ec9c3dc52302b891513f608f5fb478349b15ab3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.