Junglewise Threat Intelligence

CVE-2026-46138: Linux Kernel out-of-bounds read and infinite loop in Bluetooth HCI event handling

CVE-2026-46138 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth subsystem could allow a malicious or malfunctioning Bluetooth controller to crash the system. By sending a specially crafted Bluetooth Low Energy (LE) event, an attacker can trigger an infinite loop that freezes the operating system. This affects the availability of any device using the Linux Bluetooth stack, such as laptops, IoT devices, or servers with Bluetooth enabled.

Technical details

A vulnerability exists in the hci_le_create_big_complete_evt() function within net/bluetooth/hci_event.c. The function iterates over BT_BOUND connections for a BIG handle using a while loop without verifying that the index 'i' remains within the bounds of the 'ev->num_bis' array. If a controller sends an LE_Create_BIG_Complete event with fewer BIS handles than expected (or num_bis=0), the loop performs an out-of-bounds read into adjacent heap memory. Because the resulting invalid handles are rejected, the connection remains in the BT_BOUND state, causing the loop to repeat indefinitely while holding the 'hci_dev_lock', leading to a kernel hang (DoS). The issue is fixed by validating the number of BIS handles and terminating the BIG if setup fails.

Affected products

  • Linux Linux Kernel Fixed in 6.1.91, 6.6.31, 6.8.10, 6.9.1

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats