CVE-2026-90257: Bluetooth: virtio_bt: avoid OOB read of build info string
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: virtiobt: avoid OOB read of build info string
The virtbtsetupzephyr() sends the Zephyr vendor command 0xfc08 (Read Build Information) and hands the response to btdevinfo() and hcisetfwinfo() as a "%s" string starting at skb->data + 1, without checking the length. A backend that answers with status only leaves that pointer past the end of the received data, so the walk reads adjacent slab memory until it meets a NUL. Those bytes reach the kernel log and the firmware-info debugfs file.
To fix this, print the string with a bounded "%.s" limited to skb->len - 1. A short or unterminated response then prints as much as arrived instead of failing setup.
This mirrors commit dd068ef04412 ("Bluetooth: bpa10x: avoid OOB read of revision string in bpa10xsetup()"), which fixed the identical pattern.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel's virtio_bt Bluetooth backend are exposed when that backend processes the Zephyr Read Build Information vendor-command response. The issue depends on the response lacking the expected build-information string.
What must happen for the out-of-bounds read to occur?
The virtio Bluetooth backend must receive a status-only response to Zephyr vendor command 0xfc08, or another response too short to contain the expected string. The kernel then treats data past the received buffer as a NUL-terminated string.
What information can be exposed if the issue is triggered?
Adjacent slab-memory bytes may be read until a NUL byte is encountered. Those bytes can be written to the kernel log and exposed through the firmware-info debugfs file.