HomeDefectsLIN1025-17156
Acknowledged

LIN1025-17156 : Security Advisory - linux - CVE-2026-64126

Created: Aug 1, 2026    Updated: Aug 11, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: validate Add Extended Advertising Data length  MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command, with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size.  The handler then uses cp->adv_data_len and cp->scan_rsp_len to validate and copy cp->data, but it never checks that those bytes are part of the mgmt command payload.  A short command can therefore make add_ext_adv_data() pass an out-of-bounds pointer into tlv_data_is_valid().  If the bytes beyond the command buffer are addressable, they can also be copied into the advertising instance as scan response data, where the caller can read them back via MGMT_OP_GET_ADV_INSTANCE.  The trigger requires CAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte slab-out-of-bounds read.  Reject commands whose length does not match the fixed header plus both advertising data lengths before parsing cp->data.