CVE-2026-74532

Source
https://cve.org/CVERecord?id=CVE-2026-74532
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74532.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74532
Downstream
Published
2026-08-15T12:27:46.597Z
Modified
2026-08-17T03:47:35.656174513Z
Summary
Bluetooth: btintel: Validate length before parsing diagnostics TLV
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel: Validate length before parsing diagnostics TLV

btintel_diagnostics() accesses tlv->val[0] without first validating that the diagnostics VSE is long enough to contain that field, so may cause reading data beyond the received frame.

Fix by validating the length before access.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74532.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
af395330abed142a2685bf3d17a938544816bf3c
Fixed
c31be902ccbbb0b2c23159a1481dce80d1f9753d
Fixed
dd20e30bdbd707ea8ced581f3d7f9e9854634b17
Fixed
c618a9a5b08ea2e17bddf4e948be9f75d408fca4
Fixed
6ec9c3dc52302b891513f608f5fb478349b15ab3
Fixed
b640ff9af3c809ff5ea2077fbba17df1594ec1e4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74532.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74532.json"