Executive brief
A vulnerability in the Linux kernel's Bluetooth driver for bpa10x devices could allow a malicious or malfunctioning Bluetooth device to trigger an out-of-bounds memory read. This occurs when the system attempts to read a version string from the device without properly verifying its length. While primarily a stability or information disclosure issue, it could result in sensitive kernel memory being leaked into system logs or debug files.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the bpa10x_setup() function within the Linux kernel's Bluetooth subsystem. The driver sends a vendor-specific command (0xfc0e) and processes the response as a null-terminated string using '%s' without validating the response length (skb->len). If a device returns a truncated response or a string that is not null-terminated, the kernel continues reading adjacent slab memory until a null byte is encountered. This leaked memory is then written to the kernel log and the firmware-info debugfs file. The issue has been patched by using bounded string formatting ('%.*s') to limit the read to the actual received data length.
Affected products
- Linux Linux Kernel ddd68ec8f484 to 1813add71e386f77b3040e6c8dc9b7b3ff965a6c
Timeline
- 2026-07-01: other: Vulnerability fixed in source code
- 2026-07-27: advisory: CVE-2026-64549 published
References
- https://git.kernel.org/stable/c/1813add71e386f77b3040e6c8dc9b7b3ff965a6c
- https://git.kernel.org/stable/c/4b4008dda1d0c6e598d7865631ad4eda63a560f0
- https://git.kernel.org/stable/c/7a64f39ebe1bacd9004a62eceadac0b122ec3cc2
- https://git.kernel.org/stable/c/a8e169d308775039200bb9c905c7ce420db6e8c5
- https://git.kernel.org/stable/c/bd56c23f1f8681a2857ee924a8bd3abf87c8913b
- https://git.kernel.org/stable/c/bfc9e7be289df11e8e38c98cd78019d67fdd0bd5
- https://git.kernel.org/stable/c/dd068ef044128db655f48323a4acfd5907e04903