Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path

btmtksdio_tx_packet() rounds the transfer size up to the SDIO block size
of 256 bytes, but hands the host controller the SKB buffer as is:

err = sdio_writesb(bdev->func, MTK_REG_CTDR, skb->data,
round_up(skb->len, MTK_SDIO_BLOCK_SIZE));

Only skb->len bytes hold packet data, so the controller reads up to 255
bytes of uninitialised memory and sends it to the device over the SDIO
bus. Depending on how much tailroom slack the SKB allocation happens to
carry, that read can also extend past the end of the buffer.

Compute the padded length up front, ensure the SKB has tailroom for it,
and zero-fill the padding with skb_put_zero(). skb->len then covers the
padding, so sdio_writesb() no longer needs to round up. byte_tx keeps
counting the header and the payload only, and the error path restores the
SKB so that the caller can requeue it.

Writing behind skb->tail is only safe because the driver owns the buffer,
which "Bluetooth: btmtksdio: Take exclusive ownership of the SKB before
TX" ensures.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds DMA Read
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s Bluetooth btmtksdio driver rounds packet sizes to the 256‑byte SDIO block size before calling sdio_writesb(). Because the SKB buffer contains only the actual packet data, the driver may inadvertently read up to 255 bytes of uninitialised memory beyond skb->len before transmitting to the controller. This out‑of‑bounds DMA read can leak kernel memory contents over the SDIO bus, leading to potential information disclosure or corruption within the driver and related kernel components. The core weakness is improper buffer size handling that allows the transmission of data beyond the intended packet boundary.

Affected Systems

All Linux kernel releases that include the btmtksdio driver before the merge that zero‑fills the SKB padding are affected. No specific vendor or version list is provided, implying that every kernel build featuring this driver and lacking the fix is vulnerable.

Risk and Exploitability

The CVSS score is not published, but the EPSS indicator is less than 1%, suggesting a very low likelihood of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog, reinforcing its low risk status. Based on the description, it is inferred that an attacker would need local or privileged access to an affected MediaTek SDIO‑based Bluetooth adapter to trigger the vulnerable DMA write, resulting in kernel memory disclosure without demonstrating a remote vector or privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 03:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the btmtksdio driver patch which zero‑fills the SKB padding before DMA writes.
  • If a kernel upgrade cannot be performed immediately, disable the btmtksdio driver by blacklisting the module in /etc/modprobe.d/ or by disabling Bluetooth services that depend on MediaTek SDIO adapters.
  • As a temporary safeguard, ensure that any DMA operations are preceded by explicit boundary checks or employ a sandboxed Bluetooth stack that restricts direct access to the SDIO controller.

Generated by OpenCVE AI on September 20, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path btmtksdio_tx_packet() rounds the transfer size up to the SDIO block size of 256 bytes, but hands the host controller the SKB buffer as is: err = sdio_writesb(bdev->func, MTK_REG_CTDR, skb->data, round_up(skb->len, MTK_SDIO_BLOCK_SIZE)); Only skb->len bytes hold packet data, so the controller reads up to 255 bytes of uninitialised memory and sends it to the device over the SDIO bus. Depending on how much tailroom slack the SKB allocation happens to carry, that read can also extend past the end of the buffer. Compute the padded length up front, ensure the SKB has tailroom for it, and zero-fill the padding with skb_put_zero(). skb->len then covers the padding, so sdio_writesb() no longer needs to round up. byte_tx keeps counting the header and the payload only, and the error path restores the SKB so that the caller can requeue it. Writing behind skb->tail is only safe because the driver owns the buffer, which "Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX" ensures.
Title Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:04.844Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:00.340

Modified: 2026-09-17T17:17:00.340

Link: CVE-2026-90090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer