{"api_version":"1","generated_at":"2026-08-05T09:18:01+00:00","cve":"CVE-2026-64573","urls":{"html":"https://cve.report/CVE-2026-64573","api":"https://cve.report/api/cve/CVE-2026-64573.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64573","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64573"},"summary":{"title":"Bluetooth: qca: fix NVM tag length underflow in TLV parser","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-05 08:16:37","updated_at":"2026-08-05 08:16:37"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","name":"https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","name":"https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","name":"https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","name":"https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020","name":"https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64573","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64573","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 427281f9498ed614f9aabc80e46ec077c487da6d 70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d 59fd2f075bca94f030c7c78e94878ea0803d7690 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d a087ed960fce54e9302796229e9d545bbc9bcd4a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d 4fcfb5b2c736785464ff9745f94c6726c5ee2d85 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d c90164ca0f7036942ba088eb7ea8d3f6c2352020 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ed53949cc92e28aaa3463d246942bda1fbb7f307 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1caceadfb50432dbf6d808796cb6c34ebb6d662c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 02f05ed44b71152d5e11d29be28aed91c0489b4e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.31 6.6.148 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.159 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1.91 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8.10 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.148 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","status":"affected","version":"427281f9498ed614f9aabc80e46ec077c487da6d","versionType":"git"},{"lessThan":"59fd2f075bca94f030c7c78e94878ea0803d7690","status":"affected","version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","versionType":"git"},{"lessThan":"a087ed960fce54e9302796229e9d545bbc9bcd4a","status":"affected","version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","versionType":"git"},{"lessThan":"4fcfb5b2c736785464ff9745f94c6726c5ee2d85","status":"affected","version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","versionType":"git"},{"lessThan":"c90164ca0f7036942ba088eb7ea8d3f6c2352020","status":"affected","version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","versionType":"git"},{"status":"affected","version":"ed53949cc92e28aaa3463d246942bda1fbb7f307","versionType":"git"},{"status":"affected","version":"1caceadfb50432dbf6d808796cb6c34ebb6d662c","versionType":"git"},{"status":"affected","version":"02f05ed44b71152d5e11d29be28aed91c0489b4e","versionType":"git"},{"lessThan":"6.6.148","status":"affected","version":"6.6.31","versionType":"semver"},{"lessThan":"5.16","status":"affected","version":"5.15.159","versionType":"semver"},{"lessThan":"6.2","status":"affected","version":"6.1.91","versionType":"semver"},{"lessThan":"6.9","status":"affected","version":"6.8.10","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.9"},{"lessThan":"6.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.148","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.148","versionStartIncluding":"6.6.31","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc4","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.159","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.91","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.10","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"}],"providerMetadata":{"dateUpdated":"2026-08-05T08:08:09.669Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24"},{"url":"https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690"},{"url":"https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a"},{"url":"https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85"},{"url":"https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020"}],"title":"Bluetooth: qca: fix NVM tag length underflow in TLV parser","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64573","datePublished":"2026-08-05T08:08:09.669Z","dateReserved":"2026-07-19T15:36:31.797Z","dateUpdated":"2026-08-05T08:08:09.669Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-05 08:16:37","lastModifiedDate":"2026-08-05 08:16:37","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64573","Ordinal":"1","Title":"Bluetooth: qca: fix NVM tag length underflow in TLV parser","CVE":"CVE-2026-64573","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64573","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)","Type":"Description","Title":"Bluetooth: qca: fix NVM tag length underflow in TLV parser"}]}}}