๐Ÿ” CVE Alert

CVE-2026-72334

UNKNOWN 0.0

Bluetooth: ISO: fix malformed ISO_END/CONT handling

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix malformed ISO_END/CONT handling Core specification (Part C vol 4 sec 5.4.5) does not exclude empty ISO_CONT, ISO_END packets. We currently reject them if they are last. If controller sends malformed sequence ISO_START -> rx_len = 4, ISO_CONT skb->len 4, ISO_START that ends payload in ISO_CONT, we leak conn->rx_skb. If controller sends too long ISO_END, we panic on skb_put. If controller sends too short ISO_END we accept it. Fix by marking unfinished ISO_START via conn->rx_skb != NULL. Check skb->len properly before skb_put. Combine the ISO_CONT/END code paths as they require the same initial checks. Reject too short ISO_END packets.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ccf74f2390d60a2f9a75ef496d2564abb478f46a < 990e65eb9387c4ddfa7f68782b6644c2c35d489f ccf74f2390d60a2f9a75ef496d2564abb478f46a < e054c1a6ae7310d2815778fddb87da616e11c255
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/990e65eb9387c4ddfa7f68782b6644c2c35d489f git.kernel.org: https://git.kernel.org/stable/c/e054c1a6ae7310d2815778fddb87da616e11c255