Junglewise Threat Intelligence

CVE-2026-64549: Linux Kernel Bluetooth OOB read in bpa10x_setup

CVE-2026-64549 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Bluetooth driver for bpa10x devices could allow a malicious or malfunctioning Bluetooth device to trigger an out-of-bounds memory read. This occurs when the system attempts to read a version string from the device without properly verifying its length. While primarily a stability or information disclosure issue, it could result in sensitive kernel memory being leaked into system logs or debug files.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the bpa10x_setup() function within the Linux kernel's Bluetooth subsystem. The driver sends a vendor-specific command (0xfc0e) and processes the response as a null-terminated string using '%s' without validating the response length (skb->len). If a device returns a truncated response or a string that is not null-terminated, the kernel continues reading adjacent slab memory until a null byte is encountered. This leaked memory is then written to the kernel log and the firmware-info debugfs file. The issue has been patched by using bounded string formatting ('%.*s') to limit the read to the actual received data length.

Affected products

  • Linux Linux Kernel ddd68ec8f484 to 1813add71e386f77b3040e6c8dc9b7b3ff965a6c

Timeline

  • 2026-07-01: other: Vulnerability fixed in source code
  • 2026-07-27: advisory: CVE-2026-64549 published

References

Related threats