CVE-2026-64539: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

Greg Kroah-Hartman <[email protected]> Mon, 27 Jul 2026 22:10:37 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072735-CVE-2026-64539-4b67@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_BREDR on an LE-only controller) and then copies
the per-instance data without checking that it still fits:

	memcpy(ptr, adv->adv_data, adv->adv_data_len);

tlv_data_max_len() only reserves those 3 bytes when the user-supplied
flags carry a managed-flags bit, so an instance added with flags == 0 is
accepted with adv_data_len up to the full buffer. At advertise time the
flags are still prepended, and the memcpy() writes 3 + adv_data_len
bytes into the size-byte buffer:

  BUG: KASAN: stack-out-of-bounds in eir_create_adv_data (net/bluetooth/eir.c:301)
  Write of size 31 at addr ffff88800a547bdc by task kworker/u9:0/65
  Workqueue: hci0 hci_cmd_sync_work
   __asan_memcpy (mm/kasan/shadow.c:106)
   eir_create_adv_data (net/bluetooth/eir.c:301)
   hci_update_adv_data_sync (net/bluetooth/hci_sync.c:1310)
   hci_schedule_adv_instance_sync (net/bluetooth/hci_sync.c:1817)
   hci_cmd_sync_work (net/bluetooth/hci_sync.c:332)
  This frame has 1 object:
   [32, 64) 'cp'

The "Flags" structure is added by the kernel, not requested by
userspace, so only prepend it when it fits together with the instance
advertising data; when there is no room for both, drop the flags rather
than the user-provided data.

Reachable by a local user with CAP_NET_ADMIN owning an LE-only
controller on the legacy advertising path.

The Linux kernel CVE team has assigned CVE-2026-64539 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.1.178 with commit 0f0b6232af56441d0a2dcb173cc4f8d8aab39014
	Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.12.97 with commit 09301f1fdf2aef8cce34d0c4650c30e7edb1ced9
	Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 6.18.40 with commit f1b4df9c260c51726da2e86e19322825fddeefd0
	Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 7.1.5 with commit 57077eeb586c42f124bc09e018449362223067b3
	Issue introduced in 4.1 with commit b44133ff03be30b55f23036e62f403a3f7784fce and fixed in 7.2-rc1 with commit 6f5fb689fdf80bdd143f22a502f9eb1f3c85e286

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64539
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/bluetooth/eir.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/0f0b6232af56441d0a2dcb173cc4f8d8aab39014
	https://git.kernel.org/stable/c/09301f1fdf2aef8cce34d0c4650c30e7edb1ced9
	https://git.kernel.org/stable/c/f1b4df9c260c51726da2e86e19322825fddeefd0
	https://git.kernel.org/stable/c/57077eeb586c42f124bc09e018449362223067b3
	https://git.kernel.org/stable/c/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286