Description
In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: virtio_bt: avoid OOB read of build info string

The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read
Build Information) and hands the response to bt_dev_info() and
hci_set_fw_info() as a "%s" string starting at skb->data + 1, without
checking the length. A backend that answers with status only leaves that
pointer past the end of the received data, so the walk reads adjacent
slab memory until it meets a NUL. Those bytes reach the kernel log and
the firmware-info debugfs file.

To fix this, print the string with a bounded "%.*s" limited to
skb->len - 1. A short or unterminated response then prints as much as
arrived instead of failing setup.

This mirrors commit dd068ef04412 ("Bluetooth: bpa10x: avoid OOB read of
revision string in bpa10x_setup()"), which fixed the identical pattern.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a bug in the virtio_bt driver allows a Zephyr vendor command response to be interpreted as a zero‑terminated string without verifying the length of the data received. If the backend returns only a status byte, the driver reads past the end of the packet into adjacent slab memory until a null byte is encountered. These leaked bytes are written to the kernel log and the firmware‑info debugfs file, exposing kernel memory contents that may contain sensitive data or address information.

Affected Systems

Any Linux system using a kernel version that includes the virtio_bt module and has not incorporated the patch that bounds the Zephyr command response length (commit dd068ef). The vulnerability is present in all kernel builds where the virtio_bt driver is compiled in, regardless of configuration details.

Risk and Exploitability

The vulnerability carries a moderate confidentiality impact but a low probability of exploitation, as indicated by an EPSS score of less than 1% and its absence from the CISA KEV catalog. The likely attack vector involves a malicious or compromised Bluetooth backend or virtio_bt interface that sends an incomplete response to the Zephyr vendor command. Based on the description, it is inferred that an attacker could trigger the out‑of‑bounds read and capture fragments of kernel memory, potentially aiding in the discovery of kernel addresses or sensitive information for staged attacks. The risk is considered medium in the context of a broader security posture, especially if the driver is exposed to untrusted devices or networks.

Generated by OpenCVE AI on September 20, 2026 at 01:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch limiting the Zephyr build‑information string processing (commit dd068ef).
  • If a kernel upgrade is not immediately possible, restrict read access to the firmware‑info debugfs entry to privileged users only, thereby limiting the exposure of leaked kernel memory.
  • If the virtio_bt driver is not required, disable or remove the module from the kernel configuration or unload it with modprobe –r / blacklist the module to prevent the vulnerable code path from executing.

Generated by OpenCVE AI on September 20, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info string The virtbt_setup_zephyr() sends the Zephyr vendor command 0xfc08 (Read Build Information) and hands the response to bt_dev_info() and hci_set_fw_info() as a "%s" string starting at skb->data + 1, without checking the length. A backend that answers with status only leaves that pointer past the end of the received data, so the walk reads adjacent slab memory until it meets a NUL. Those bytes reach the kernel log and the firmware-info debugfs file. To fix this, print the string with a bounded "%.*s" limited to skb->len - 1. A short or unterminated response then prints as much as arrived instead of failing setup. This mirrors commit dd068ef04412 ("Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()"), which fixed the identical pattern.
Title Bluetooth: virtio_bt: avoid OOB read of build info string
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:56.089Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.087

Modified: 2026-09-17T17:17:22.087

Link: CVE-2026-90257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:15:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor