Bluetooth: virtio_bt: avoid OOB read of build info string
Summary
| CVE | CVE-2026-90257 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:22 UTC |
| Updated | 2026-09-17 17:17:22 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: virtio_bt: avoid OOB read of build info string
The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read
Build Information) and hands the response to bt_dev_info() and
hci_set_fw_info() as a "%s" string starting at skb->data + 1, without
checking the length. A backend that answers with status only leaves that
pointer past the end of the received data, so the walk reads adjacent
slab memory until it meets a NUL. Those bytes reach the kernel log and
the firmware-info debugfs file.
To fix this, print the string with a bounded "%.*s" limited to
skb->len - 1. A short or unterminated response then prints as much as
arrived instead of failing setup.
This mirrors commit dd068ef04412 ("Bluetooth: bpa10x: avoid OOB read of
revision string in bpa10x_setup()"), which fixed the identical pattern. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 fb445b3466a8d1c7a0b0d0676fb475e3ce22d94e git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 d08c99abf06133a7829d46627e77e3315ca974d2 git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 0e388d805233a883a31271676eae6031dfc9e898 git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 54e9387eb7546eaa6f600220599d55740956ffc3 git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 be1e3df2c49c91b0a052c6563884e8d39bd768b2 git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 84ea9c99874804f5ca13f35bbc186ba93902f30f git |
Not specified |
| CNA |
Linux |
Linux |
affected afd2daa26c7abd734d78bd274fc6c59a15e61063 502adc06ba76dee19c292ae4a07d74d202fe734d git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.13 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.13 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/502adc06ba76dee19c292ae4a07d74d202fe734d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/84ea9c99874804f5ca13f35bbc186ba93902f30f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0e388d805233a883a31271676eae6031dfc9e898 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/be1e3df2c49c91b0a052c6563884e8d39bd768b2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/54e9387eb7546eaa6f600220599d55740956ffc3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fb445b3466a8d1c7a0b0d0676fb475e3ce22d94e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d08c99abf06133a7829d46627e77e3315ca974d2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.