PT-2026-72191 · Linux · Linux Kernel
CVE-2026-68479
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Bluetooth component where the
rtlbt parse firmware() function fails to properly validate firmware patch bounds. When processing a malformed firmware patch shorter than the version field, a subtraction underflow occurs during the copy of patch length - 4 bytes. This can lead to oversized read and write operations during Bluetooth setup. Additionally, on 32-bit architectures, the check involving patch offset + patch length is susceptible to wrapping, which can cause arithmetic overflow during patch allocation or copying.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel