CVE-2026-31497 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: clamp SCO altsetting table indices btusb_work() maps the number of active SCO links to USB alternate settings through a three-entry lookup table when CVSD traffic uses transparent voice settings. The lookup currently indexes alts[] with data->sco_num - 1 without first constraining sco_num to the number of available table entries. While the table only defines alternate settings for up to three SCO links, data->sco_num comes from hci_conn_num() and is used directly. Cap the lookup to the last table entry before indexing it so the driver keeps selecting the highest supported alternate setting without reading past alts[].
A vulnerability in the Bluetooth btusb driver of the Linux kernel allows for improper handling of USB alternate settings related to SCO (Synchronous Connection-Oriented) links. When CVSD (Continuous Variable Slope Delta) audio is transmitted using transparent voice settings, the driver maps active SCO links to USB alternate settings through a three-entry lookup table. However, the current implementation does not properly constrain the index used to access the table, potentially leading to out-of-bounds reads. This issue affects the Linux kernel's stable releases.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1019028eb124564cf7bca58a16f1df8a1ca30726 | kernel.org | Patch |
| https://git.kernel.org/stable/c/129fa608b6ad08b8ab7178eeb2ec272c993aaccc | kernel.org | Patch |
| https://git.kernel.org/stable/c/21c254202f9d78abe0fcd642a92966deb92bd226 | kernel.org | Patch |
| https://git.kernel.org/stable/c/312c4450fe23014665c163f480edd5ad2e27bbb8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/476c9262b430c38c6a701a3b8176a3f48689085b | kernel.org | Patch |
| https://git.kernel.org/stable/c/6fba3c3d48c927e55611a0f5ea34da88138ed0ff | kernel.org | Patch |
| https://git.kernel.org/stable/c/834cf890d2c3d29cbfa1ee2376c40469c28ec297 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9dd13a8641de79bc1bc93da55cdd35259a002683 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.8.1, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.131 >= 6.7, < 6.12.80 >= 6.13, < 6.18.21 >= 6.19, < 6.19.11 5.8 - 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | New CVE Received | kernel.org |