๐Ÿ” CVE Alert

CVE-2026-89583

HIGH 8.1

Bluetooth: eir: Fix OOB read in eir_get_service_data()

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
8f9ae5b3ae80f168a6224529e3787f4fb27f299a < b6902adf81ea2ce14b1040dd97b6980050a8125a 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 1a28aae7f1fc8c06c0d02f153541be4fc7bacb74 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 815fc98c227a78cbd93d4c29f2833705b7c2bc0f 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < c21fa79301d7d6ac0a4ec6c51e8ba10beaa08c50 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < bb56e97bd67614238c1c0a4084704ccadbb875b4 8f9ae5b3ae80f168a6224529e3787f4fb27f299a < 4beb198bc59b242404a47c21990bc84165052c8a
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b6902adf81ea2ce14b1040dd97b6980050a8125a git.kernel.org: https://git.kernel.org/stable/c/1a28aae7f1fc8c06c0d02f153541be4fc7bacb74 git.kernel.org: https://git.kernel.org/stable/c/815fc98c227a78cbd93d4c29f2833705b7c2bc0f git.kernel.org: https://git.kernel.org/stable/c/c21fa79301d7d6ac0a4ec6c51e8ba10beaa08c50 git.kernel.org: https://git.kernel.org/stable/c/bb56e97bd67614238c1c0a4084704ccadbb875b4 git.kernel.org: https://git.kernel.org/stable/c/4beb198bc59b242404a47c21990bc84165052c8a