PT-2026-94437 · Linux · Linux Kernel

CVE-2026-90089

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Bluetooth btnxpuart component where the nxp process fw dump() function reads seq num and buf len from a nxp fw dump hdr structure without verifying if the ACL payload is sufficiently long to contain the header. Because h4 recv buf() relies on a length provided by the controller, a short frame with a connection handle of 0xfff can cause the system to read these fields from beyond the received data. Additionally, if buf len is zero due to a truncated frame, the driver may call hci devcd complete() and reset the controller, prematurely ending a dump.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90089
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel