PT-2026-36406 · Linux · Linux Kernel

CVE-2026-31771

·

Published

2026-05-01

·

Updated

2026-08-30

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth component where hci store wake reason() is called within hci event packet() before the per-event minimum payload length is enforced by hci event func(). This allows a short HCI event frame to reach bacpy() before any bounds check is performed. The fix involves moving wake-address storage into individual event handlers after length validation has succeeded and converting hci store wake reason() into a helper function that stores a validated bdaddr while holding the hci dev lock(). This helper is utilized by several functions, including hci conn request evt(), hci conn complete evt(), hci sync conn complete evt(), le conn complete evt(), hci le adv report evt(), hci le ext adv report evt(), hci le direct adv report evt(), hci le pa sync established evt(), and hci le past received evt().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-85380
CVE-2026-31771
OESA-2026-2416
OESA-2026-2581
OESA-2026-2582
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22436-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:22460-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:2632-1
SUSE-SU-2026:2799-1
SUSE-SU-2026:2800-1
SUSE-SU-2026:2840-1
SUSE-SU-2026:2841-1
SUSE-SU-2026:3044-1
SUSE-SU-2026:3089-1

Affected Products

Linux Kernel