Answer in brief
CVE-2026-68479 records a Unknown severity vulnerability in Bluetooth: btrtl: validate firmware patch bounds. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-68479 records a Unknown severity vulnerability in Bluetooth: btrtl: validate firmware patch bounds. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <39e01b4addfbbe177567d6ed1dfb81f9cccb19e6 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <bda3c598ade6ea03884074b91e31608326684921 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <a4cb830e0b55ac76c849fd7840afb251f4c028fa || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <68c5a2a19987c035eb129e627e579adafb04f637 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <83534891c058ed71e251135072640911670869aa || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <6744ab60dfac55d1df5733960aad5be300984301 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <f1ca750c0510bdbb504bf084d2f196ef2af92ea6 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <609c5b04a28dc1b0f3af6a7bc93055135b2d2059 | 39e01b4addfbbe177567d6ed1dfb81f9cccb19e6, bda3c598ade6ea03884074b91e31608326684921, a4cb830e0b55ac76c849fd7840afb251f4c028fa, 68c5a2a19987c035eb129e627e579adafb04f637, 83534891c058ed71e251135072640911670869aa, 6744ab60dfac55d1df5733960aad5be300984301, f1ca750c0510bdbb504bf084d2f196ef2af92ea6, 609c5b04a28dc1b0f3af6a7bc93055135b2d2059 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmware patch bounds rtlbt_parse_firmware() copies patch_length - 4 bytes before appending the firmware version. A malformed firmware patch shorter than the version field can make this subtraction underflow and turn the copy into an oversized read and write during Bluetooth setup. The existing patch_offset + patch_length check can also wrap on 32-bit architectures. Validate the patch length and range without arithmetic overflow before allocating or copying the patch.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <39e01b4addfbbe177567d6ed1dfb81f9cccb19e6 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <bda3c598ade6ea03884074b91e31608326684921 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <a4cb830e0b55ac76c849fd7840afb251f4c028fa || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <68c5a2a19987c035eb129e627e579adafb04f637 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <83534891c058ed71e251135072640911670869aa || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <6744ab60dfac55d1df5733960aad5be300984301 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <f1ca750c0510bdbb504bf084d2f196ef2af92ea6 || >=db33c77dddc2ed2cff3061d0b096a9f5ab0c3647 <609c5b04a28dc1b0f3af6a7bc93055135b2d2059 | 39e01b4addfbbe177567d6ed1dfb81f9cccb19e6, bda3c598ade6ea03884074b91e31608326684921, a4cb830e0b55ac76c849fd7840afb251f4c028fa, 68c5a2a19987c035eb129e627e579adafb04f637, 83534891c058ed71e251135072640911670869aa, 6744ab60dfac55d1df5733960aad5be300984301, f1ca750c0510bdbb504bf084d2f196ef2af92ea6, 609c5b04a28dc1b0f3af6a7bc93055135b2d2059 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmware patch bounds rtlbt_parse_firmware() copies patch_length - 4 bytes before appending the firmware version. A malformed firmware patch shorter than the version field can make this subtraction underflow and turn the copy into an oversized read and write during Bluetooth setup. The existing patch_offset + patch_length check can also wrap on 32-bit architectures. Validate the patch length and range without arithmetic overflow before allocating or copying the patch.
Quoted source text, attributed separately from HOL analysis.