CVE-2026-64573: Bluetooth: qca: fix NVM tag length underflow in TLV parser

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026080500-CVE-2026-64573-d88e@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: qca: fix NVM tag length underflow in TLV parser

In the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is
"while (idx < length - sizeof(struct tlv_type_nvm))". "length" is a signed
int from the firmware TLV header and sizeof(struct tlv_type_nvm) is a
size_t (12), so "length" is converted to size_t and any firmware-supplied
"length" < 12 makes the subtraction wrap to a huge value. The loop body
then reads a 12-byte struct tlv_type_nvm past the end of the short
vmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).

Rewrite the bound as "idx + sizeof(struct tlv_type_nvm) <= length"; both
operands are non-negative, so it no longer underflows and a "length" too
small for one record correctly skips the loop.

  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)
  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52
  Workqueue: hci0 hci_power_on
  Call Trace:
   ...
   kasan_report (mm/kasan/report.c:595)
   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)
   qca_uart_setup (drivers/bluetooth/btqca.c:948)
   qca_setup (drivers/bluetooth/hci_qca.c:2029)
   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)
   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)
   hci_power_on (net/bluetooth/hci_core.c:920)
   process_one_work (kernel/workqueue.c:3322)
   worker_thread (kernel/workqueue.c:3486)
   kthread (kernel/kthread.c:436)
   ret_from_fork (arch/x86/kernel/process.c:158)
   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)

The Linux kernel CVE team has assigned CVE-2026-64573 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.6.31 with commit 427281f9498ed614f9aabc80e46ec077c487da6d and fixed in 6.6.148 with commit 70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24
	Issue introduced in 6.9 with commit 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d and fixed in 6.12.101 with commit 59fd2f075bca94f030c7c78e94878ea0803d7690
	Issue introduced in 6.9 with commit 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d and fixed in 6.18.42 with commit a087ed960fce54e9302796229e9d545bbc9bcd4a
	Issue introduced in 6.9 with commit 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d and fixed in 7.1.6 with commit 4fcfb5b2c736785464ff9745f94c6726c5ee2d85
	Issue introduced in 6.9 with commit 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d and fixed in 7.2-rc4 with commit c90164ca0f7036942ba088eb7ea8d3f6c2352020
	Issue introduced in 5.15.159 with commit ed53949cc92e28aaa3463d246942bda1fbb7f307
	Issue introduced in 6.1.91 with commit 1caceadfb50432dbf6d808796cb6c34ebb6d662c
	Issue introduced in 6.8.10 with commit 02f05ed44b71152d5e11d29be28aed91c0489b4e

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64573
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/bluetooth/btqca.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24
	https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690
	https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a
	https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85
	https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.