CVE-2026-98292: Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access
btmtksdio.c and btmtkuart.c cast a received WMT event straight to struct btmtkhciwmtevt and read its op/flag fields without checking the event is long enough to contain them, unlike btmtk.c. The FUNCCTRL case then further casts to struct btmtkhciwmtevtfuncc and reads its 2-byte status field, again without a length check. Firmware that sends a short or malformed WMT event makes both drivers read past the end of the received SKB.
Mirror btmtk.c: validate the base WMT header with skbpulldata() before touching any of its fields, and when a FUNCCTRL event turns out to be the short, header-only form (a plain enable/disable ack with no status word), decode the result from the header's own flag byte instead (0 = success, otherwise failure).
Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.