Bluetooth: hci_aml: validate firmware segment lengths
Summary
| CVE | CVE-2026-80759 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-04 16:18:00 UTC |
| Updated | 2026-09-04 16:18:00 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_aml: validate firmware segment lengths
aml_download_firmware() reads two lengths from the firmware header and
uses them to build pointers before checking that the header and segment
data are present. A truncated or inconsistent firmware image can make
the driver read past firmware->data while constructing TCI commands.
Reject images shorter than the header and ensure that the ICCM and DCCM
ranges fit within the loaded firmware before downloading either segment. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 37bac77e4649e8158698a60addc22ec4faf5649a 7733b01ed13685773ccda91035a46f87d4cfef7c git |
Not specified |
| CNA |
Linux |
Linux |
affected 37bac77e4649e8158698a60addc22ec4faf5649a e1534d49a7b8ba728e84b020f6d802aa1cb759d9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 37bac77e4649e8158698a60addc22ec4faf5649a 6c70253462902d835e843b470f74aa816d60af80 git |
Not specified |
| CNA |
Linux |
Linux |
affected 37bac77e4649e8158698a60addc22ec4faf5649a 2763b8bcb504e30ec955474f51b99ce42fc62f3b git |
Not specified |
| CNA |
Linux |
Linux |
affected 37bac77e4649e8158698a60addc22ec4faf5649a 2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.106 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.47 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.11 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.1 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e1534d49a7b8ba728e84b020f6d802aa1cb759d9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6c70253462902d835e843b470f74aa816d60af80 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2763b8bcb504e30ec955474f51b99ce42fc62f3b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7733b01ed13685773ccda91035a46f87d4cfef7c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.