Impact
This flaw concerns the Bluetooth stack in the Linux kernel. When a Microsoft‑specific event response arrives, the driver incorrectly trusts a length byte in the payload that indicates the size of a flexible array. It copies up to 255 bytes from the payload regardless of the actual length of the data sent, resulting in the kernel reading bytes that were never transmitted by the controller. Because the copy operation stops before the end of the skb buffer, no out‑of‑bounds error is triggered, but the host reads stale kernel memory. The data is then used by the vendor event matching logic, potentially leaking kernel contents. This constitutes a kernel information‑disclosure vulnerability.
Affected Systems
The vulnerability affects the Linux kernel’s Bluetooth subsystem, specifically the Microsoft (MSFT) vendor extension used by various drivers such as btintel, btqca, btmtk, and btrtl. No specific kernel version numbers are provided; any kernel build containing the affected code is potentially affected. Remediation requires a kernel update that incorporates the patch that rejects responses with an inconsistent prefix length.
Risk and Exploitability
The CVSS score is not listed, and the EPSS score is below 1 %, indicating a low probability of exploitation currently. The flaw is not listed in the CISA KEV. Attackers would need to control the Bluetooth controller sending the crafted response to the host, implying a local attack with physical or remote over‑the‑air access to the device. The lack of detectable bounds errors means standard kernel hardening will not detect the issue, yet the presence of a vulnerability that leaks kernel data is a serious concern for systems that expose Bluetooth services.
OpenCVE Enrichment
Debian DLA
Debian DSA