Answer in brief
CVE-2026-64126 records a Unknown severity vulnerability in Bluetooth: MGMT: validate Add Extended Advertising Data length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64126 records a Unknown severity vulnerability in Bluetooth: MGMT: validate Add Extended Advertising Data length. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=12410572833a283ce92fcf9679ca8a2f372097ee <0d5104390b445e7bd664ad583837e4c04d892c9d || >=12410572833a283ce92fcf9679ca8a2f372097ee <14b01b9cba04e6ce82825f68fc4c4322fa4ffa43 || >=12410572833a283ce92fcf9679ca8a2f372097ee <a143ce77a5292f2c9285137433d879ce71d190a7 || >=12410572833a283ce92fcf9679ca8a2f372097ee <a6c75a3fad226ccbd8ef9110dee87c92c299f2ab || >=12410572833a283ce92fcf9679ca8a2f372097ee <f1febe93ef075314615f970a87681d9ab86691d1 || >=12410572833a283ce92fcf9679ca8a2f372097ee <0bc1a5a69f541859293d79db72bd7854ac48df51 || >=12410572833a283ce92fcf9679ca8a2f372097ee <d3f7d17960ed50df3a6709c5158caff989c8c905 | 0d5104390b445e7bd664ad583837e4c04d892c9d, 14b01b9cba04e6ce82825f68fc4c4322fa4ffa43, a143ce77a5292f2c9285137433d879ce71d190a7, a6c75a3fad226ccbd8ef9110dee87c92c299f2ab, f1febe93ef075314615f970a87681d9ab86691d1, 0bc1a5a69f541859293d79db72bd7854ac48df51, d3f7d17960ed50df3a6709c5158caff989c8c905 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising Data length MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command, with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. The handler then uses cp->adv_data_len and cp->scan_rsp_len to validate and copy cp->data, but it never checks that those bytes are part of the mgmt command payload. A short command can therefore make add_ext_adv_data() pass an out-of-bounds pointer into tlv_data_is_valid(). If the bytes beyond the command buffer are addressable, they can also be copied into the advertising instance as scan response data, where the caller can read them back via MGMT_OP_GET_ADV_INSTANCE. The trigger requires CAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte slab-out-of-bounds read. Reject commands whose length does not match the fixed header plus both advertising data lengths before parsing cp->data.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=12410572833a283ce92fcf9679ca8a2f372097ee <0d5104390b445e7bd664ad583837e4c04d892c9d || >=12410572833a283ce92fcf9679ca8a2f372097ee <14b01b9cba04e6ce82825f68fc4c4322fa4ffa43 || >=12410572833a283ce92fcf9679ca8a2f372097ee <a143ce77a5292f2c9285137433d879ce71d190a7 || >=12410572833a283ce92fcf9679ca8a2f372097ee <a6c75a3fad226ccbd8ef9110dee87c92c299f2ab || >=12410572833a283ce92fcf9679ca8a2f372097ee <f1febe93ef075314615f970a87681d9ab86691d1 || >=12410572833a283ce92fcf9679ca8a2f372097ee <0bc1a5a69f541859293d79db72bd7854ac48df51 || >=12410572833a283ce92fcf9679ca8a2f372097ee <d3f7d17960ed50df3a6709c5158caff989c8c905 | 0d5104390b445e7bd664ad583837e4c04d892c9d, 14b01b9cba04e6ce82825f68fc4c4322fa4ffa43, a143ce77a5292f2c9285137433d879ce71d190a7, a6c75a3fad226ccbd8ef9110dee87c92c299f2ab, f1febe93ef075314615f970a87681d9ab86691d1, 0bc1a5a69f541859293d79db72bd7854ac48df51, d3f7d17960ed50df3a6709c5158caff989c8c905 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising Data length MGMT_OP_ADD_EXT_ADV_DATA is registered as a variable-length command, with MGMT_ADD_EXT_ADV_DATA_SIZE as the fixed header size. The handler then uses cp->adv_data_len and cp->scan_rsp_len to validate and copy cp->data, but it never checks that those bytes are part of the mgmt command payload. A short command can therefore make add_ext_adv_data() pass an out-of-bounds pointer into tlv_data_is_valid(). If the bytes beyond the command buffer are addressable, they can also be copied into the advertising instance as scan response data, where the caller can read them back via MGMT_OP_GET_ADV_INSTANCE. The trigger requires CAP_NET_ADMIN in the initial user namespace; KASAN reports an 8-byte slab-out-of-bounds read. Reject commands whose length does not match the fixed header plus both advertising data lengths before parsing cp->data.
Quoted source text, attributed separately from HOL analysis.