CVE-2026-98111

Unknown

Last modified

CVE-2026-98111 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: validate version TLV value lengths btintel_parse_version_tlv() verifies that a complete TLV is present in the response, but it does not ensure that the value is long enough for the specific TLV type. A short value can therefore cause an out-of-bounds read through get_unaligned_le16(), get_unaligned_le32(), or memcpy(). Reject values shorter than the minimum required by each known TLV type. Also reject responses that do not contain the Command Complete Status field..

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: validate version TLV value lengths btintel_parse_version_tlv() verifies that a complete TLV is present in the response, but it does not ensure that the value is long enough for the specific TLV type. A short value can therefore cause an out-of-bounds read through get_unaligned_le16(), get_unaligned_le32(), or memcpy(). Reject values shorter than the minimum required by each known TLV type. Also reject responses that do not contain the Command Complete Status field.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 57375beef71af9f245e88357fa71d9600650cb7d, < 83499ac3ca62e43ed40f7574b13ed398a6891511; >= 57375beef71af9f245e88357fa71d9600650cb7d, < 76948d207d0978a613ce06a05cba07284a5578a7; >= 57375beef71af9f245e88357fa71d9600650cb7d, < 5ec43df2830b73e004147303bf7914ca884d6770; >= 57375beef71af9f245e88357fa71d9600650cb7d, < a086c0892969bf8a0151b0f12bd14a68827c88b2
LinuxLinux5.10

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-98111?
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: validate version TLV value lengths btintel_parse_version_tlv() verifies that a complete TLV is present in the response, but it does not ensure that the value is long enough for the specific TLV type. A short value can therefore cause an out-of-bounds read through get_unaligned_le16(), get_unaligned_le32(), or memcpy(). Reject values shorter than the minimum required by each known TLV type. Also reject responses that do not contain the Command Complete Status field.
How severe is CVE-2026-98111?
Severity scoring for CVE-2026-98111 is pending analysis.
How do I fix CVE-2026-98111?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-98111?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST