Bluetooth Vulnerability in Linux Kernel Affects Various Products
CVE-2026-98111

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98111?

A vulnerability identified within the Bluetooth component of the Linux Kernel allows for potential out-of-bounds reads due to inadequate validation of TLV (Type-Length-Value) lengths. The function responsible for parsing version TLV does not verify if the value length meets minimum requirements for defined TLV types, which could lead to unauthorized memory access and potentially harmful exploitation. To mitigate this risk, it is crucial to implement checks that enforce minimum value lengths and ensure responses include the necessary Command Complete Status field.

Affected Version(s)

Linux 57375beef71af9f245e88357fa71d9600650cb7d < 83499ac3ca62e43ed40f7574b13ed398a6891511

Linux 57375beef71af9f245e88357fa71d9600650cb7d < 76948d207d0978a613ce06a05cba07284a5578a7

Linux 57375beef71af9f245e88357fa71d9600650cb7d < 5ec43df2830b73e004147303bf7914ca884d6770

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.