CVE-2026-89583
CVE CVE-2026-89583EUVD EUVD-2026-76495Veröffentlicht 2026-09-11T19:44:49.000ZZuletzt geändert 2026-09-14T12:01:11.000ZCVSS 8.1
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <b6902adf81ea2ce14b1040dd97b6980050a8125a; 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <1a28aae7f1fc8c06c0d02f153541be4fc7bacb74; 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <c21fa79301d7d6ac0a4ec6c51e8ba10beaa08c50; patch: 6.1.188; 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <4beb198bc59b242404a47c21990bc84165052c8a; patch: 7.3-rc1; patch: 7.2.4; 5.19; patch: 6.12.109; patch: 0; 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <815fc98c227a78cbd93d4c29f2833705b7c2bc0f; 8f9ae5b3ae80f168a6224529e3787f4fb27f299a <bb56e97bd67614238c1c0a4084704ccadbb875b4; patch: 6.6.157; patch: 6.18.50
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.