Bluetooth Vulnerability in Linux Kernel Affecting Qualcomm QCA Devices
CVE-2026-64573
What is CVE-2026-64573?
A vulnerability in the Linux kernel's Bluetooth subsystem could allow a malicious firmware to exploit the TLV parser, leading to buffer overflow due to incorrect handling of tag lengths. Specifically, this flaw occurs in the qca_tlv_check_data() function, where the condition for looping through the firmware data uses a signed integer for length. If the firmware provides a length less than the necessary size, it can cause the subtraction to underflow, resulting in accessing memory outside the allocated buffer. This issue could potentially lead to arbitrary code execution or system crashes, making it imperative for users to update their devices to the latest kernel version that resolves this vulnerability.
Affected Version(s)
Linux 427281f9498ed614f9aabc80e46ec077c487da6d < 70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24
Linux 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d < 59fd2f075bca94f030c7c78e94878ea0803d7690
Linux 2e4edfa1e2bd821a317e7d006517dcf2f3fac68d