| Summary | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid() reads each advertising data field length from A malformed field whose length byte is the last byte of the buffer can KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid() Move the existing element-length check before any type-octet inspection |
|---|---|
| Publication Date | June 25, 2026, 6:16 p.m. |
| Registration Date | June 27, 2026, 4:27 a.m. |
| Last Update | June 25, 2026, 6:16 p.m. |