Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3444 articles · 168093 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-53255EXPLOITEDPATCHED
linux · linux kernel

Bluetooth: MGMT: validate advertising TLV before type checks

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid() reads each advertising data field length from data[i], then inspects data[i + 1] for managed EIR types before checking that the current field still fits inside the supplied buffer. A malformed field whose length byte is the last byte of the buffer can therefore make the parser read one byte past the advertising data. KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING request reached that path: BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid() Read of size 1 Call trace: tlv_data_is_valid() add_advertising() hci_mgmt_cmd() hci_sock_sendmsg() Move the existing element-length check before any type-octet inspection so each non-empty element is proven to contain its type byte before the parser looks at data[i + 1].

Affected Products

VendorProductVersions
linuxlinux kernel2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 2bb36870e8cb29949ef9acec37129cd8e70f1857, 4.9, 7.0.12, 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, 7.0.13, 7.1

References

  • https://git.kernel.org/stable/c/13ad995071a06570668dd8daab3616c247c72080
  • https://git.kernel.org/stable/c/06fcbd79c3c360a50f9be9d370769bbd738d0976
  • https://git.kernel.org/stable/c/f7093ac233c1e7f51d125534f46067772a113175
  • https://git.kernel.org/stable/c/74c08e4db35a476c3462aeb65846f955be732626
  • https://git.kernel.org/stable/c/18fea1cb0c2599752e908c8217490f73ddd33e00
  • https://git.kernel.org/stable/c/1a3c8ffbb469859b076445af44bdfa6a711d483e
  • https://git.kernel.org/stable/c/2a3f3ed9e198ae23c15859ace2f9ca6cfdc35b57
  • https://git.kernel.org/stable/c/de23fb62259aa01d294f77238ae3b835eb674413

Related News (3 articles)

Tier A
Microsoft MSRC1h ago
CVE-2026-53255 Bluetooth: MGMT: validate advertising TLV before type checks
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-53255 | Linux Kernel up to 7.0.12 Bluetooth tlv_data_is_valid length out-of-bounds
→ No new info (linked only)
Tier C
Linux Kernel CVEs3d ago
CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
13ad995071a06570668dd8daab3616c247c7208006fcbd79c3c360a50f9be9d370769bbd738d0976f7093ac233c1e7f51d125534f46067772a11317574c08e4db35a476c3462aeb65846f955be73262618fea1cb0c2599752e908c8217490f73ddd33e001a3c8ffbb469859b076445af44bdfa6a711d483e2a3f3ed9e198ae23c15859ace2f9ca6cfdc35b57de23fb62259aa01d294f77238ae3b835eb67441305.10.2595.15.2106.1.1766.6.1436.12.946.18.367.0.137.1
PublishedJun 25, 2026
Last enriched2d agov3
Trending Score65
Source articles3
Independent3
Info Completeness8/14
Missing: cvss, epss, cwe, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 111
HIGHCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 106
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 100
HIGHCVE-2026-46243EXP
smb: client: reject userspace cifs.spnego descriptions
Trending: 86
HIGHCVE-2026-46333EXP
ptrace: slightly saner 'get_dumpable()' logic
Trending: 70

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Actively Exploited
Jun 25, 2026
Exploit Available
Jun 25, 2026
Patch Available
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Updated: description, affectedVersions, severity
Jun 25, 2026
Updated: description, affectedVersions, exploitAvailable, activelyExploited
Jun 25, 2026

Version History

v3
Last enriched 2d ago
v3Tier C2d ago

Updated description with technical details, added affected versions, and marked exploit availability as true.

descriptionaffectedVersionsexploitAvailableactivelyExploited
via Linux Kernel CVEs
v2Tier C3d ago

Updated description with critical severity, added affected version 7.0.12, and noted that no exploit exists.

descriptionaffectedVersionsseverity
via VulDB
v13d ago

Initial creation