CVE-2026-80760
Last modified
CVE-2026-80760 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message length agrees with params_len but puts no upper bound on it. params_len is __le16 while the parameter length in the HCI command header is a u8: struct hci_command_hdr { __le16 opcode; __u8 plen; } __packed; hci_cmd_sync_alloc() assigns one to the other: hdr->plen = plen; if (plen) skb_put_data(skb, param, plen); so a params_len of 256 leaves plen at 0 while all 256 bytes are still appended.
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message length agrees with params_len but puts no upper bound on it. params_len is __le16 while the parameter length in the HCI command header is a u8: struct hci_command_hdr { __le16 opcode; __u8 plen; } __packed; hci_cmd_sync_alloc() assigns one to the other: hdr->plen = plen; if (plen) skb_put_data(skb, param, plen); so a params_len of 256 leaves plen at 0 while all 256 bytes are still appended. The frame handed to the driver then declares no parameters and carries 256 of them. On a length framed transport such as H:4 the controller takes the trailing bytes as the start of the next packet. The mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params_len can reach about 1KB this way. Commit 03f1700b9b4d ("Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands") only made params_len agree with the message length, a value that fits the message but not the header field is still accepted. Reject params_len that does not fit the header field.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f, < b7d9edcf9fe6e9ec3a2e80ef9e8d44ef9b4f2894; >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f, < 0bd0195ce25737cbdd0eabc54319ee0ddf3a0ad2; >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f, < 6e1c44878aa3ee7336efeaf01414b030b0a5c273; >= 827af4787e74e8df9e8e0677a69fbb15e0856d2f, < 5d95286b6d6e8f1d304da7522bfa6860fc017e48 |
| Linux | Linux | 6.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80760?
How severe is CVE-2026-80760?
How do I fix CVE-2026-80760?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80755In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80756In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80757In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80758In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80759In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8076Weak credentials in the CashDro 3 web administration panel, …9.3
- CVE-2026-80761In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80762In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80763In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80764In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80765In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80766In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80760?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
