CVE-2026-46140
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/05/2026
Última modificación:
28/05/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Bluetooth: btmtk: validate WMT event SKB length before struct access<br />
<br />
btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to<br />
struct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc<br />
(9 bytes) without first checking that the SKB contains enough data.<br />
A short firmware response causes out-of-bounds reads from SKB tailroom.<br />
<br />
Use skb_pull_data() to validate and advance past the base WMT event<br />
header. For the FUNC_CTRL case, pull the additional status field bytes<br />
before accessing them.



