CVE-2026-46138 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration. However, there is no check that i stays within ev->num_bis before the array access. When a controller sends a LE_Create_BIG_Complete event with fewer bis_handle entries than there are BT_BOUND connections for that BIG, or with num_bis=0, the loop reads beyond the valid bis_handle[] flex array into adjacent heap memory. Since the out-of-bounds values typically exceed HCI_CONN_HANDLE_MAX (0x0EFF), hci_conn_set_handle() rejects them and the connection remains in BT_BOUND state. The same connection is then found again by hci_conn_hash_lookup_big_state(), creating an infinite loop with hci_dev_lock held. Fix this by terminating the BIG if in case not all BIS could be setup properly.
A vulnerability in the Linux kernel's Bluetooth implementation allows for an out-of-bounds read and an infinite loop condition. This issue arises in the 'hci_le_create_big_complete_evt' function, which processes 'LE_Create_BIG_Complete' events. The function iterates over Bluetooth connections, accessing an array of handles without proper bounds checking. When a controller sends an event with fewer handles than expected, or with no handles at all, the function reads beyond the valid array into adjacent heap memory. This out-of-bounds access typically involves values that exceed the maximum connection handle limit, causing the connection to remain in a bound state. The same connection is then reprocessed, leading to an infinite loop while holding a device lock.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/22559ad7654f61727fc270ee4893da9f4b70cf17 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5ddb8014261137cadaf83ab5617a588d80a22586 | kernel.org | Patch |
| https://git.kernel.org/stable/c/665da0baaf0396f9ed3c86ccb3955dcd0b73e774 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6cb7f67bc28da787499291a562d49a084d9c90cd | kernel.org | Patch |
| https://git.kernel.org/stable/c/77981a507aa0fc001dc37f0dd6631dd2042fed17 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.4.16, < 6.5 >= 6.5.3, < 6.6.140 >= 6.7, < 6.12.88 >= 6.13, < 6.18.30 >= 6.19, < 7.0.7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |