Impact
In the Linux kernel, a bug in the virtio_bt driver allows a Zephyr vendor command response to be interpreted as a zero‑terminated string without verifying the length of the data received. If the backend returns only a status byte, the driver reads past the end of the packet into adjacent slab memory until a null byte is encountered. These leaked bytes are written to the kernel log and the firmware‑info debugfs file, exposing kernel memory contents that may contain sensitive data or address information.
Affected Systems
Any Linux system using a kernel version that includes the virtio_bt module and has not incorporated the patch that bounds the Zephyr command response length (commit dd068ef). The vulnerability is present in all kernel builds where the virtio_bt driver is compiled in, regardless of configuration details.
Risk and Exploitability
The vulnerability carries a moderate confidentiality impact but a low probability of exploitation, as indicated by an EPSS score of less than 1% and its absence from the CISA KEV catalog. The likely attack vector involves a malicious or compromised Bluetooth backend or virtio_bt interface that sends an incomplete response to the Zephyr vendor command. Based on the description, it is inferred that an attacker could trigger the out‑of‑bounds read and capture fragments of kernel memory, potentially aiding in the discovery of kernel addresses or sensitive information for staged attacks. The risk is considered medium in the context of a broader security posture, especially if the driver is exposed to untrusted devices or networks.
OpenCVE Enrichment
Debian DLA
Debian DSA