CVE-2026-89583
Received Received - Intake

Bluetooth OOB Read in Linux Kernel

Vulnerability report for CVE-2026-89583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
linux linux_kernel *
linux_kernel linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Bluetooth vulnerability in the Linux kernel where eir_get_service_data() incorrectly calculates buffer lengths while parsing advertising data. It leads to an out-of-bounds read as the pointer moves past the end of the allocated buffer, potentially exposing kernel memory to user space via ISO broadcast sink data.

Detection Guidance

This vulnerability involves an out-of-bounds (OOB) read in the Linux kernel's Bluetooth eir_get_service_data() function. Detection requires kernel-level inspection for memory corruption or unexpected Bluetooth stack behavior. Monitor system logs for Bluetooth-related crashes or errors. Use kernel debugging tools like ftrace or perf to trace Bluetooth-related function calls. Check for abnormal memory access patterns in Bluetooth-related processes.

Impact Analysis

An attacker could exploit this to read sensitive kernel memory, potentially leaking passwords, encryption keys, or other confidential data. On systems using Bluetooth ISO broadcast sinks, user space could access this data via getsockopt(BT_ISO_BASE).

Compliance Impact

This vulnerability involves an out-of-bounds (OOB) read in the Linux kernel's Bluetooth handling, potentially exposing memory contents to user space. While not directly tied to GDPR or HIPAA, such flaws could lead to unauthorized data exposure, impacting compliance if sensitive data is leaked. However, specific compliance impacts depend on deployment context and data processed.

Mitigation Strategies

Apply the latest Linux kernel security patches immediately. Update to a kernel version that includes the fix for CVE-2026-89583. Disable Bluetooth if not in use or restrict Bluetooth functionality to trusted devices. Monitor vendor advisories for additional mitigation steps. Consider isolating Bluetooth-related services in a sandboxed environment until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart