๐Ÿ” CVE Alert

CVE-2026-43017

UNKNOWN 0.0

Bluetooth: MGMT: validate mesh send advertising payload length

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate mesh send advertising payload length mesh_send() currently bounds MGMT_OP_MESH_SEND by total command length, but it never verifies that the bytes supplied for the flexible adv_data[] array actually match the embedded adv_data_len field. MGMT_MESH_SEND_SIZE only covers the fixed header, so a truncated command can still pass the existing 20..50 byte range check and later drive the async mesh send path past the end of the queued command buffer. Keep rejecting zero-length and oversized advertising payloads, but validate adv_data_len explicitly and require the command length to exactly match the flexible array size before queueing the request.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 1, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < 24fa32369cf15d8fc918bdfe94097b12e6acada0 b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < 244b639e6a3a8e26241e201004a3a9f764476631 b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < 0b706fb2294aff3adfd54653bda1b5e356ad4566 b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < edb5898cfa91afe7e8f83eda18d93034c953d632 b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < 562ed1954f0c1bff3422b7b752bd3dacf185edbf b338d91703fae6f6afd67f3f75caa3b8f36ddef3 < bda93eec78cdbfe5cda00785cefebd443e56b88b
Linux / Linux
6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/24fa32369cf15d8fc918bdfe94097b12e6acada0 git.kernel.org: https://git.kernel.org/stable/c/244b639e6a3a8e26241e201004a3a9f764476631 git.kernel.org: https://git.kernel.org/stable/c/0b706fb2294aff3adfd54653bda1b5e356ad4566 git.kernel.org: https://git.kernel.org/stable/c/edb5898cfa91afe7e8f83eda18d93034c953d632 git.kernel.org: https://git.kernel.org/stable/c/562ed1954f0c1bff3422b7b752bd3dacf185edbf git.kernel.org: https://git.kernel.org/stable/c/bda93eec78cdbfe5cda00785cefebd443e56b88b