CVE-2026-53255 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid() reads each advertising data field length from data[i], then inspects data[i + 1] for managed EIR types before checking that the current field still fits inside the supplied buffer. A malformed field whose length byte is the last byte of the buffer can therefore make the parser read one byte past the advertising data. KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING request reached that path: BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid() Read of size 1 Call trace: tlv_data_is_valid() add_advertising() hci_mgmt_cmd() hci_sock_sendmsg() Move the existing element-length check before any type-octet inspection so each non-empty element is proven to contain its type byte before the parser looks at data[i + 1].
A vulnerability in the Linux kernel's Bluetooth management layer allows for out-of-bounds memory access when processing advertising data. The issue arises in the 'tlv_data_is_valid' function, which reads the length of each advertising data field and checks its type. A malformed length byte can cause the parser to read beyond the intended buffer, leading to memory corruption. This vulnerability was detected by the Kernel Address Sanitizer (KASAN) when a malformed 'MGMT_OP_ADD_ADVERTISING' request was processed, resulting in a 'vmalloc-out-of-bounds' error. The vulnerability affects the Linux kernel stable tree.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/06fcbd79c3c360a50f9be9d370769bbd738d0976 | kernel.org | Patch |
| https://git.kernel.org/stable/c/13ad995071a06570668dd8daab3616c247c72080 | kernel.org | Patch |
| https://git.kernel.org/stable/c/18fea1cb0c2599752e908c8217490f73ddd33e00 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1a3c8ffbb469859b076445af44bdfa6a711d483e | kernel.org | Patch |
| https://git.kernel.org/stable/c/2a3f3ed9e198ae23c15859ace2f9ca6cfdc35b57 | kernel.org | Patch |
| https://git.kernel.org/stable/c/74c08e4db35a476c3462aeb65846f955be732626 | kernel.org | Patch |
| https://git.kernel.org/stable/c/de23fb62259aa01d294f77238ae3b835eb674413 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f7093ac233c1e7f51d125534f46067772a113175 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.9, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | New CVE Received | kernel.org |