{"api_version":"1","generated_at":"2026-07-20T14:42:28+00:00","cve":"CVE-2026-64128","urls":{"html":"https://cve.report/CVE-2026-64128","api":"https://cve.report/api/cve/CVE-2026-64128.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64128","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64128"},"summary":{"title":"Bluetooth: ISO: drop ISO_END frames received without prior ISO_START","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn->rx_len before touching conn->rx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn->rx_skb is still NULL and conn->rx_len is zero, so\nskb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:54","updated_at":"2026-07-19 16:17:54"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f","name":"https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f","name":"https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728","name":"https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129","name":"https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b","name":"https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63","name":"https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64128","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64128","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a 1c3d1e1696b72579b970e17999c503a14535205b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a 3af41ee7ebecb0d5c8a504861f6cfad31345310f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a 39f4a82e80c8f5ed2d6952d73fbafc895721a728 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a 61f2410a96dee808029e2ae4d6ef2dd635f3477f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a e3a799881c12d27596232636a607e2e3fa448d63 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ccf74f2390d60a2f9a75ef496d2564abb478f46a 84c24fb151fc1179355296d7ff29129ac7c42129 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.175 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.142 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.92 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"1c3d1e1696b72579b970e17999c503a14535205b","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"},{"lessThan":"3af41ee7ebecb0d5c8a504861f6cfad31345310f","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"},{"lessThan":"39f4a82e80c8f5ed2d6952d73fbafc895721a728","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"},{"lessThan":"61f2410a96dee808029e2ae4d6ef2dd635f3477f","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"},{"lessThan":"e3a799881c12d27596232636a607e2e3fa448d63","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"},{"lessThan":"84c24fb151fc1179355296d7ff29129ac7c42129","status":"affected","version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.0"},{"lessThan":"6.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.175","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.142","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.92","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"6.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn->rx_len before touching conn->rx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn->rx_skb is still NULL and conn->rx_len is zero, so\nskb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host."}],"providerMetadata":{"dateUpdated":"2026-07-19T15:40:24.678Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/1c3d1e1696b72579b970e17999c503a14535205b"},{"url":"https://git.kernel.org/stable/c/3af41ee7ebecb0d5c8a504861f6cfad31345310f"},{"url":"https://git.kernel.org/stable/c/39f4a82e80c8f5ed2d6952d73fbafc895721a728"},{"url":"https://git.kernel.org/stable/c/61f2410a96dee808029e2ae4d6ef2dd635f3477f"},{"url":"https://git.kernel.org/stable/c/e3a799881c12d27596232636a607e2e3fa448d63"},{"url":"https://git.kernel.org/stable/c/84c24fb151fc1179355296d7ff29129ac7c42129"}],"title":"Bluetooth: ISO: drop ISO_END frames received without prior ISO_START","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64128","datePublished":"2026-07-19T15:40:24.678Z","dateReserved":"2026-07-19T07:54:57.036Z","dateUpdated":"2026-07-19T15:40:24.678Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:54","lastModifiedDate":"2026-07-19 16:17:54","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64128","Ordinal":"1","Title":"Bluetooth: ISO: drop ISO_END frames received without prior ISO_S","CVE":"CVE-2026-64128","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64128","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn->rx_len before touching conn->rx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn->rx_skb is still NULL and conn->rx_len is zero, so\nskb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host.","Type":"Description","Title":"Bluetooth: ISO: drop ISO_END frames received without prior ISO_S"}]}}}