Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btrtl: validate firmware patch bounds

rtlbt_parse_firmware() copies patch_length - 4 bytes before appending the
firmware version. A malformed firmware patch shorter than the version field
can make this subtraction underflow and turn the copy into an oversized
read and write during Bluetooth setup.

The existing patch_offset + patch_length check can also wrap on 32-bit
architectures. Validate the patch length and range without arithmetic
overflow before allocating or copying the patch.
Published: 2026-08-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The btrtl Bluetooth driver in the Linux kernel contains an integer underflow that occurs when parsing a malformed firmware patch. If the patch length is shorter than expected, the subtraction can underflow, turning a copy operation into an oversized read and write during the firmware installation process. This results in kernel memory corruption and can crash the system or potentially allow an attacker to gain elevated privileges. The weakness is a classic integer-overflow leading to a buffer overflow scenario, aliased as CWE-680 and CWE-122.

Affected Systems

All Linux kernel instances that implement the btrtl Bluetooth driver are vulnerable, regardless of distribution. No specific version range is provided, so any kernel release that includes the unpatched btrtl code before the referenced commit is susceptible.

Risk and Exploitability

An attacker would need to deliver a crafted firmware patch over the Bluetooth interface. The vulnerability can trigger on 32‑bit architectures where arithmetic wraparound is possible, increasing the likelihood of exploitation on such systems. While no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, the potential for kernel memory corruption and elevation of privileges means the risk is high if the target device accepts external firmware updates. Disabling Bluetooth or the btrtl driver is a mitigative step until a patch is applied.

Generated by OpenCVE AI on August 15, 2026 at 21:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the btrtl fix committed in the provided patches
  • If an immediate kernel upgrade is not possible, unload or disable the btrtl driver and turn off Bluetooth services to prevent firmware update attempts
  • Verify any firmware updates against official signed images or trusted repositories to ensure only legitimate patches are applied

Generated by OpenCVE AI on August 15, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-680

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmware patch bounds rtlbt_parse_firmware() copies patch_length - 4 bytes before appending the firmware version. A malformed firmware patch shorter than the version field can make this subtraction underflow and turn the copy into an oversized read and write during Bluetooth setup. The existing patch_offset + patch_length check can also wrap on 32-bit architectures. Validate the patch length and range without arithmetic overflow before allocating or copying the patch.
Title Bluetooth: btrtl: validate firmware patch bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:51:34.106Z

Reserved: 2026-07-30T09:28:09.397Z

Link: CVE-2026-68479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:20:51.380

Modified: 2026-08-15T06:20:51.380

Link: CVE-2026-68479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T21:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-680

    Integer Overflow to Buffer Overflow