{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74508","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.908Z","datePublished":"2026-08-15T12:27:31.288Z","dateUpdated":"2026-08-23T12:47:28.838Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-23T12:47:28.838Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: reject frames without a transaction header\n\nhidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0]\nbefore checking that the L2CAP SDU contains a transaction header. A\nconnected HIDP peer can send an empty basic-mode SDU and make both paths\nuse an uninitialized byte from skb tailroom.\n\nKMSAN reports the use in hidp_session_run(), with the uninitialized value\noriginating in __alloc_skb() through vhci_write(). The control path\nproduces two reports and the interrupt path produces one.\n\nThe byte can also be controlled by a malformed lower-layer packet. If an\nHCI ACL packet contains an L2CAP PDU with a declared zero-length payload\nfollowed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to\nthe declared PDU length before dispatch. The current HIDP path nevertheless\nconsumes the extra byte as HIDP_TRANS_HID_CONTROL |\nHIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this\nchange, the same packet is discarded and a subsequent feature report\nrequest succeeds.\n\nPull the transaction header with skb_pull_data() and discard frames that\ndo not contain it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - Malicious or malformed Bluetooth L2CAP SDUs reach hidp_recv_ctrl_frame()/hidp_recv_intr_frame() from a radio-adjacent peer via hci_acl_packet() -> l2cap_recv_acldata() -> l2cap_recv_frame() -> l2cap_sock_recv_cb() -> hidp_session_run().\nAC:L - A connected HIDP peer reliably triggers the bug by sending empty basic-mode SDUs or zero-length L2CAP PDUs with trailing bytes; the attacker controls both sides of the malformed-packet condition without races or rare kernel configs.\nPR:N - Exploitation requires only delivering crafted Bluetooth ACL/L2CAP traffic as the connected peer; the victim attacker does not need local accounts, capabilities, or CAP_NET_ADMIN on the target host.\nUI:N - Once a normal Bluetooth HID session is active (typical paired keyboard/mouse/headset use), the attacker can send malicious frames without any additional victim interaction during exploitation.\nS:U - The flaw affects kernel Bluetooth HIDP session handling only and does not cross VM, container, or IOMMU security boundaries; impact stays within the kernel Bluetooth/HID authority.\nC:H - On zero-length SDUs, hidp_recv_*_frame() reads skb->data[0] from uninitialized skb tailroom (KMSAN via vhci_write/__alloc_skb), leaking kernel heap bytes that drive subsequent protocol parsing.\nI:H - Attacker-controlled header bytes (e.g., malformed PDU trailing 0x15 = HIDP_TRANS_HID_CONTROL|HIDP_CTRL_VIRTUAL_CABLE_UNPLUG) force hidp_process_hid_control() to tear down sessions and can misroute other transaction types through handshake/data handlers.\nA:H - Forged virtual-cable-unplug and related control-path handling forcibly terminates active HIDP sessions, completely denying Bluetooth HID input/output on phones, laptops, kiosks, and embedded systems until reconnect."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hidp/core.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"238c333bc4b3f245c626632e8bfa3c9dab97f51b","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"567a2a0a633f2ea5fdccaf3517c09f22c9d860c7","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"97b61241ab45bfa5b0526cb0f3978942493bc811","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2ebf63aa557a69990b4e9ea22be224d58aabce96","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"854194494a6f726a60b90b76059148bf08df023d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"47778d2c2087b5d192398f6fddf692d16a5431cf","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/hidp/core.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.266"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/24c64ccd5c1fc9934b427335b0d976c7f2b1a7d8"},{"url":"https://git.kernel.org/stable/c/238c333bc4b3f245c626632e8bfa3c9dab97f51b"},{"url":"https://git.kernel.org/stable/c/567a2a0a633f2ea5fdccaf3517c09f22c9d860c7"},{"url":"https://git.kernel.org/stable/c/46ca5ab39737d7c6f9ca77ecf714cdcfa6caaeec"},{"url":"https://git.kernel.org/stable/c/97b61241ab45bfa5b0526cb0f3978942493bc811"},{"url":"https://git.kernel.org/stable/c/2ebf63aa557a69990b4e9ea22be224d58aabce96"},{"url":"https://git.kernel.org/stable/c/854194494a6f726a60b90b76059148bf08df023d"},{"url":"https://git.kernel.org/stable/c/47778d2c2087b5d192398f6fddf692d16a5431cf"}],"title":"Bluetooth: HIDP: reject frames without a transaction header","x_generator":{"engine":"bippy-1.2.0"}}}}