PT-2026-94437 · Linux · Linux Kernel
CVE-2026-90089
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Bluetooth
btnxpuart component where the nxp process fw dump() function reads seq num and buf len from a nxp fw dump hdr structure without verifying if the ACL payload is sufficiently long to contain the header. Because h4 recv buf() relies on a length provided by the controller, a short frame with a connection handle of 0xfff can cause the system to read these fields from beyond the received data. Additionally, if buf len is zero due to a truncated frame, the driver may call hci devcd complete() and reset the controller, prematurely ending a dump.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel