Impact
The Linux kernel’s Bluetooth btmtksdio driver rounds packet sizes to the 256‑byte SDIO block size before calling sdio_writesb(). Because the SKB buffer contains only the actual packet data, the driver may inadvertently read up to 255 bytes of uninitialised memory beyond skb->len before transmitting to the controller. This out‑of‑bounds DMA read can leak kernel memory contents over the SDIO bus, leading to potential information disclosure or corruption within the driver and related kernel components. The core weakness is improper buffer size handling that allows the transmission of data beyond the intended packet boundary.
Affected Systems
All Linux kernel releases that include the btmtksdio driver before the merge that zero‑fills the SKB padding are affected. No specific vendor or version list is provided, implying that every kernel build featuring this driver and lacking the fix is vulnerable.
Risk and Exploitability
The CVSS score is not published, but the EPSS indicator is less than 1%, suggesting a very low likelihood of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog, reinforcing its low risk status. Based on the description, it is inferred that an attacker would need local or privileged access to an affected MediaTek SDIO‑based Bluetooth adapter to trigger the vulnerable DMA write, resulting in kernel memory disclosure without demonstrating a remote vector or privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA