CVE-2026-64539: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
Greg Kroah-Hartman <[email protected]> Mon, 27 Jul 2026 22:10:37 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072735-CVE-2026-64539-4b67@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD eir_create_adv_data() builds the advertising data into a fixed-size buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags" AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies the per-instance data without checking that it still fits: memcpy(ptr, adv->adv_data, adv->adv_data_len); tlv_data_max_len() only reserves those 3 bytes when the user-supplied flags carry a managed-flags bit, so an instance added with flags == 0 is accepted with adv_data_len up to the full buffer. At advertise time the flags are still prepended, and the memcpy() writes 3 + adv_data_len bytes into the size-byte buffer: BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301) Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65 Workqueue: hci0 hci_cmd_sync_work __asan_memcpy (mm/kasan/shadow.c:106) eir_create_adv_data (net/bluetooth/eir.c:301) hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310) hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817) hci_cmd_sync_work (net/bluetooth/hci_sync.c:332) This frame has 1 object: [32, 64) 'cp' The "Flags" structure is added by the kernel, not requested by userspace, so only prepend it when it fits together with the instance advertising data; when there is no room for both, drop the flags rather than the user-provided data. Reachable by a local user with CAP_NET_ADMIN owning an LE-only controller on the legacy advertising path. The Linux kernel CVE team has assigned CVE-2026-64539 to this issue. Affected and fixed versions =========================== Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.1.178 with commit 0f0b6232af56441d0a2dcb173cc4f8d8aab39014 Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.12.97 with commit 09301f1fdf2aef8cce34d0c4650c30e7edb1ced9 Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.18.40 with commit f1b4df9c260c51726da2e86e19322825fddeefd0 Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 7.1.5 with commit 57077eeb586c42f124bc09e018449362223067b3 Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 7.2-rc1 with commit 6f5fb689fdf80bdd143f22a502f9eb1f3c85e286 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64539 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/bluetooth/eir.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0f0b6232af56441d0a2dcb173cc4f8d8aab39014 https://git.kernel.org/stable/c/09301f1fdf2aef8cce34d0c4650c30e7edb1ced9 https://git.kernel.org/stable/c/f1b4df9c260c51726da2e86e19322825fddeefd0 https://git.kernel.org/stable/c/57077eeb586c42f124bc09e018449362223067b3 https://git.kernel.org/stable/c/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286