Impact
Ignoring the required transaction header, the HIDP layer reads an uninitialized byte from the packet. In a Bluetooth HID device stream, a crafted empty SDU or malformed lower‑layer packet can supply this byte, causing the kernel to use it as a control code. This leads to the termination of the HIDP session, disrupting the Bluetooth service and resulting in a denial of service. The flaw arises from uninitialized memory usage.
Affected Systems
Linux kernel builds that have not incorporated the commit adding the transaction‑header verification are vulnerable. Any distribution running a kernel version before the patch and which has the HIDP module enabled and Bluetooth stack active will be susceptible. Systems that disable Bluetooth HIDP or do not load the module are unaffected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, but the EPSS score of less than 1% suggests an extremely low exploitation probability. The flaw is not listed in CISA’s KEV catalog. Exploitation requires a malicious Bluetooth HID device that can send specially crafted packets, which can be delivered at physical proximity to the target. No local privileges or system authentication are required, and the impact is limited to the Bluetooth service and the device’s responsiveness.
OpenCVE Enrichment
Debian DSA