PT-2026-94438 · Linux · Linux Kernel
CVE-2026-90090
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds DMA read exists in the TX path of the Bluetooth
btmtksdio driver. The btmtksdio tx packet() function rounds the transfer size up to the SDIO block size of 256 bytes while providing the SKB buffer as is. Because only skb->len bytes contain actual packet data, the controller may read up to 255 bytes of uninitialized memory and transmit it over the SDIO bus. Depending on the tailroom slack of the SKB allocation, this read can extend beyond the end of the buffer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel