CVE-2026-98110

Source
https://cve.org/CVERecord?id=CVE-2026-98110
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98110.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98110
Downstream
Published
2026-09-25T10:35:58Z
Modified
2026-09-26T03:48:37Z
Summary
Bluetooth: btintel: bound firmware ID by TLV length
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel: bound firmware ID by TLV length

The firmware ID is treated as a NUL-terminated string even though the TLV length is its only boundary. If the value does not contain a NUL terminator, snprintf() can read beyond the received response.

Limit the conversion to the advertised TLV value length.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98110.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
164c62f958f8c7f0bde1e9a5a8677971c6f28205
Fixed
aef56a2bd5aa22808ce508605d7497d2b5e8eb5f
Fixed
058f56de5f48ba4b3be01526006ac83ce9e79f39
Fixed
a07b3024a927892dd46e7dfbed438e8834e24098
Fixed
ac8aa9e0ec93a12a60230066f199f49c3b9aac3d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98110.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98110.json"