PT-2026-52350 · Linux+1 · Linux Kernel+1

CVE-2026-53255

·

Published

2026-06-25

·

Updated

2026-09-07

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth MGMT component where the tlv data is valid() function reads the advertising data field length from data[i] and inspects data[i + 1] for managed EIR (Enhanced Inquiry Response) types before verifying if the current field fits within the supplied buffer. A malformed field with a length byte positioned as the last byte of the buffer can cause the parser to read one byte beyond the advertising data, leading to a vmalloc-out-of-bounds read when processing a MGMT OP ADD ADVERTISING request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90680
CVE-2026-53255
ECHO-7ADB-EC5B-8F9F
OESA-2026-3204
OESA-2026-3206
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
SUSE-SU-2026:3594-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu