CVE-2026-98111

Source
https://cve.org/CVERecord?id=CVE-2026-98111
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98111.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98111
Downstream
Published
2026-09-25T10:35:58Z
Modified
2026-09-26T03:48:37Z
Summary
Bluetooth: btintel: validate version TLV value lengths
Details

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btintel: validate version TLV value lengths

btintel_parse_version_tlv() verifies that a complete TLV is present in the response, but it does not ensure that the value is long enough for the specific TLV type. A short value can therefore cause an out-of-bounds read through get_unaligned_le16(), get_unaligned_le32(), or memcpy().

Reject values shorter than the minimum required by each known TLV type. Also reject responses that do not contain the Command Complete Status field.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98111.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
57375beef71af9f245e88357fa71d9600650cb7d
Fixed
83499ac3ca62e43ed40f7574b13ed398a6891511
Fixed
76948d207d0978a613ce06a05cba07284a5578a7
Fixed
5ec43df2830b73e004147303bf7914ca884d6770
Fixed
a086c0892969bf8a0151b0f12bd14a68827c88b2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98111.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98111.json"