Linux Kernel Bluetooth bpa10x OOB Read of Revision String
CVE-2026-64549 Published on July 27, 2026
Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
bpa10x_setup() sends the vendor command 0xfc0e and passes the response
to bt_dev_info() and hci_set_fw_info() as a "%s" string starting at
skb->data + 1, without checking the length:
bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
hci_set_fw_info(hdev, "%s", skb->data + 1);
A device that returns a one-byte response (status only) leaves
skb->data + 1 past the end of the data, and the %s walk reads adjacent
slab memory until it meets a NUL. The same happens when the payload is
not NUL-terminated within skb->len. The out-of-bounds bytes end up in
the kernel log and the firmware-info debugfs file.
Print the revision string with a bounded "%.*s" limited to skb->len - 1
instead. This keeps the string readable for well-behaved devices while
never reading past the received data, and does not fail setup, so a
device returning a short or unterminated response keeps working.
Products Associated with CVE-2026-64549
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below 1813add71e386f77b3040e6c8dc9b7b3ff965a6c is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below bd56c23f1f8681a2857ee924a8bd3abf87c8913b is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below 7a64f39ebe1bacd9004a62eceadac0b122ec3cc2 is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below f80b4afe893dffa9fabdbf80fb4d6782b24a6793 is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below 4b4008dda1d0c6e598d7865631ad4eda63a560f0 is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below bfc9e7be289df11e8e38c98cd78019d67fdd0bd5 is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below a8e169d308775039200bb9c905c7ce420db6e8c5 is affected.
- Version ddd68ec8f4847b460c9f580076eafe13b031a6fd and below dd068ef044128db655f48323a4acfd5907e04903 is affected.
- Version 4.4 is affected.
- Before 4.4 is unaffected.
- Version 5.10.261, <= 5.10.* is unaffected.
- Version 5.15.212, <= 5.15.* is unaffected.
- Version 6.1.178, <= 6.1.* is unaffected.
- Version 6.6.145, <= 6.6.* is unaffected.
- Version 6.12.97, <= 6.12.* is unaffected.
- Version 6.18.40, <= 6.18.* is unaffected.
- Version 7.1.5, <= 7.1.* is unaffected.
- Version 7.2-rc3, <= * is unaffected.