PT-2026-94438 · Linux · Linux Kernel

CVE-2026-90090

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds DMA read exists in the TX path of the Bluetooth btmtksdio driver. The btmtksdio tx packet() function rounds the transfer size up to the SDIO block size of 256 bytes while providing the SKB buffer as is. Because only skb->len bytes contain actual packet data, the controller may read up to 255 bytes of uninitialized memory and transmit it over the SDIO bus. Depending on the tailroom slack of the SKB allocation, this read can extend beyond the end of the buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102075
CVE-2026-90090
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel