{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90089","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.786Z","datePublished":"2026-09-17T16:06:04.201Z","dateUpdated":"2026-09-18T17:52:55.438Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:52:55.438Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Validate the FW dump header length\n\nnxp_process_fw_dump() pulls the ACL header off the frame and then reads\nseq_num and buf_len from a struct nxp_fw_dump_hdr placed at skb->data,\nwithout checking that the ACL payload is long enough to contain it.\n\nh4_recv_buf() collects HCI_ACL_HDR_SIZE bytes of header followed by the\nnumber of payload bytes named in that header, so skb->len is 4 + dlen\nwith dlen supplied by the controller and possibly smaller than the 8\nbyte dump header, or zero. A short frame with connection handle 0xfff\ntherefore reads both fields from beyond the received data.\n\nBeyond the read itself, buf_len is what terminates a dump: a value of\nzero makes the driver call hci_devcd_complete() and reset the\ncontroller, so a truncated frame can end a dump early.\n\nUse skb_pull_data() to validate and pull the FW dump header before\naccessing its fields. Warn and reject the chunk if the header is\ntruncated."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The malformed nxp_fw_dump_hdr is taken from HCI ACL frames with connection handle 0xFFF. Those frames are assembled by h4_recv_buf() from UART bytes in btnxpuart_receive_buf() and dispatched by nxp_recv_acl_pkt() into nxp_process_fw_dump(). A nearby attacker who induces an NXP firmware dump over the air supplies that ACL dump chunk; Bluetooth range is Adjacent.\nAC:L - nxp_process_fw_dump() loads seq_num and buf_len after skb_pull_data() of only the 4-byte HCI ACL header. h4_recv_buf() delivers any dlen the controller advertised, including zero, so one handle-0xFFF ACL with dlen<8 deterministically over-reads with no race or uninfluenced layout.\nPR:N - nxp_recv_acl_pkt() and nxp_process_fw_dump() run on the serdev RX path with no pairing, HCI authentication, or capability check; handle 0xFFF dump chunks are consumed before they reach the normal HCI ACL stack.\nUI:N - btnxpuart_receive_buf() always passes complete H4 ACL frames to nxp_recv_acl_pkt(); no user must pair, confirm a prompt, or write the HCI coredump sysfs entry for a dump chunk to be parsed.\nS:U - The over-read, hci_devcd_init/append/complete dump state, and nxp_set_ind_reset() controller reset all stay in the host kernel's btnxpuart/HCI authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:L - After pulling the ACL header, the driver loads the 8-byte nxp_fw_dump_hdr (seq_num and buf_len) from skb->data even when skb->len is 0–7. That is a strictly bounded 8-byte over-read of the H4 ACL skb tailroom allocated at HCI_MAX_FRAME_SIZE, and those fields are never copied to userspace.\nI:N - The path only reads seq_num/buf_len to decide dump start/complete and does not write past the skb; hci_devcd_append() copies only skb->len valid bytes, so there is no OOB write or control-flow hijack primitive.\nA:H - When the over-read buf_len is 0, nxp_process_fw_dump() calls hci_devcd_complete() and nxp_set_ind_reset(), which injects HCI_EV_HARDWARE_ERROR 0xb0 (BTNXPUART_IR_HW_ERR) and runs the independent-reset path (nxp_hw_err → HCI_NXP_IND_RESET), taking the Bluetooth controller down; a truncated handle-0xFFF frame can repeat this at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/bluetooth/btnxpuart.c"],"versions":[{"version":"998e447f443f138c90faa6ff3845082af419070e","lessThan":"a644b8df94966b672ac656577df98bd01bc88393","status":"affected","versionType":"git"},{"version":"998e447f443f138c90faa6ff3845082af419070e","lessThan":"22d419db7f9a01bea22cfcf66774d2b2fd4bb354","status":"affected","versionType":"git"},{"version":"998e447f443f138c90faa6ff3845082af419070e","lessThan":"060fa7592bdc043a93b6b7870f5b8551206d315d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/bluetooth/btnxpuart.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a644b8df94966b672ac656577df98bd01bc88393"},{"url":"https://git.kernel.org/stable/c/22d419db7f9a01bea22cfcf66774d2b2fd4bb354"},{"url":"https://git.kernel.org/stable/c/060fa7592bdc043a93b6b7870f5b8551206d315d"}],"title":"Bluetooth: btnxpuart: Validate the FW dump header length","x_generator":{"engine":"bippy-1.2.0"}}}}