{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89583","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.728Z","datePublished":"2026-09-11T19:44:49.094Z","dateUpdated":"2026-09-14T12:01:11.801Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:11.801Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: eir: Fix OOB read in eir_get_service_data()\n\neir_get_service_data() walks the advertising data for a Service Data\nfield with a matching UUID.  On a mismatch it advances:\n\n    eir += dlen;\n    eir_len -= dlen;\n\neir_get_data() reports dlen as the field's data length, but the field\nspans dlen + 2 bytes once its length and type bytes count, and more\nwhen non-Service-Data fields were skipped to reach it.  The pointer\nlands correctly on the next field.  eir_len does not, and the shortfall\ncompounds across fields until eir_get_data() reads the length and type\nbytes of a \"field\" past the end of the buffer.\n\nFor an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled\nfrom the periodic advertising reports of a remote broadcaster.  A PA\npayload packed with mismatching Service Data fields walks off the array\ninto the rest of struct hci_conn.  A drifted field that matches the BAA\nUUID puts those bytes in iso_pi(sk)->base, where user space reads them\nback with getsockopt(BT_ISO_BASE).\n\nRecompute eir_len from the end of the buffer each iteration."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The OOB read is in eir_get_service_data() parsing LE periodic advertising. An ISO broadcast sink copies HCI_EV_LE_PER_ADV_REPORT payloads from a remote broadcaster into hcon->le_per_adv_data[] via iso_connect_ind(), which is an adjacent Bluetooth radio path, not IP or a local-only syscall.\nAC:L - An in-range attacker fully controls the PA payload and can pack mismatching Service Data fields to inflate eir_len, then a trailing BAA-UUID field whose declared length extends past the buffer; triggering is deterministic with no race or layout the attacker cannot influence.\nPR:N - Periodic advertising is unauthenticated connectionless LE traffic; iso_connect_ind() parses PA reports with no pairing, HCI authentication, or capability check, and iso_sock_create() has no CAP_NET_ADMIN gate, so the attacker needs no Linux credentials on the victim.\nUI:N - LE Audio/Auracast stacks keep ISO broadcast-sink listeners during normal operation; once PA sync exists, iso_connect_ind() parses each HCI_EV_LE_PER_ADV_REPORT automatically and returns HCI_LM_ACCEPT without further user clicks, pairing, or setup.\nS:U - The out-of-bounds read of struct hci_conn and the copy into the ISO socket BASE buffer remain in the host kernel Bluetooth stack and do not cross a VM, container, or IOMMU security boundary.\nC:H - Inflated eir_len lets a matching BAA (0x1851) Service Data field extend past the 1650-byte le_per_adv_data[] into the rest of hci_conn; up to BASE_MAX_LENGTH (248) bytes are memcpy'd into iso_pi(sk)->base and returned via getsockopt(BT_ISO_BASE), leaking kernel pointers and adjacent object bytes.\nI:N - This is an out-of-bounds read only; the memcpy into iso_pi(sk)->base is capped by BASE_MAX_LENGTH, and there is no out-of-bounds write, use-after-free, or control-flow hijack primitive.\nA:H - Continuing the EIR walk with an overstated remaining length can read hundreds of bytes past le_per_adv_data[] into adjacent slab or unmapped memory, causing a kernel oops or KASAN panic that the attacker can retrigger with further PA reports."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/eir.c"],"versions":[{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"b6902adf81ea2ce14b1040dd97b6980050a8125a","status":"affected","versionType":"git"},{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"1a28aae7f1fc8c06c0d02f153541be4fc7bacb74","status":"affected","versionType":"git"},{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"815fc98c227a78cbd93d4c29f2833705b7c2bc0f","status":"affected","versionType":"git"},{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"c21fa79301d7d6ac0a4ec6c51e8ba10beaa08c50","status":"affected","versionType":"git"},{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"bb56e97bd67614238c1c0a4084704ccadbb875b4","status":"affected","versionType":"git"},{"version":"8f9ae5b3ae80f168a6224529e3787f4fb27f299a","lessThan":"4beb198bc59b242404a47c21990bc84165052c8a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/bluetooth/eir.c"],"versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b6902adf81ea2ce14b1040dd97b6980050a8125a"},{"url":"https://git.kernel.org/stable/c/1a28aae7f1fc8c06c0d02f153541be4fc7bacb74"},{"url":"https://git.kernel.org/stable/c/815fc98c227a78cbd93d4c29f2833705b7c2bc0f"},{"url":"https://git.kernel.org/stable/c/c21fa79301d7d6ac0a4ec6c51e8ba10beaa08c50"},{"url":"https://git.kernel.org/stable/c/bb56e97bd67614238c1c0a4084704ccadbb875b4"},{"url":"https://git.kernel.org/stable/c/4beb198bc59b242404a47c21990bc84165052c8a"}],"title":"Bluetooth: eir: Fix OOB read in eir_get_service_data()","x_generator":{"engine":"bippy-1.2.0"}}}}