CVE 7.8 HIGH

Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync_CVE-2026-31772

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync

hci_le_big_create_sync() uses DEFINE_FLEX to allocate a
struct hci_cp_le_big_create_sync on the stack with room for 0x11 (17)
BIS entries. However, conn->num_bis can hold up to HCI_MAX_ISO_BIS (31)
entries — validated against ISO_MAX_NUM_BIS (0x1f) in the caller
hci_conn_big_create_sync(). When conn->num_bis is between 18 and 31,
the memcpy that copies conn->bis into cp->bis writes up to 14 bytes
past the stack buffer, corrupting adjacent stack memory.

This is trivially reproducible: binding an ISO socket with
bc_num_bis = ISO_MAX_NUM_BIS (31) and calling listen() will
eventually trigger hci_le_big_create_sync() from the HCI command
sync worker, causing a KASAN-detectable stack-out-of-bounds write:

BUG: KASAN: stack-out-of-bounds in hci_le_big_create_sync+0x256/0x3b0
Write of size 31 at addr ffffc90000487b48 by task kworker/u9:0/71

Fix this by changing the DEFINE_FLEX count from the incorrect 0x11 to
HCI_MAX_ISO_BIS, which matches the maximum number of BIS entries that
conn->bis can actually carry.

Basic Information

ID CVE-2026-31772
Source Linux
Published May 1, 2026 at 14:15
Modified May 3, 2026 at 05:45

Affected Product

Vendor Linux
Product Linux
Version 91d19383b7ed035e22165ae5c836e50bb9f95fbe
Affected Versions Linux Linux 91d19383b7ed035e22165ae5c836e50bb9f95fbe
Linux Linux 42ecf1947135110ea08abeaca39741636f9a2285
Linux Linux 42ecf1947135110ea08abeaca39741636f9a2285
Linux Linux 42ecf1947135110ea08abeaca39741636f9a2285
Linux Linux 8958e1cee4e2eac1a5b825caa4dd96ce9ed975dd
Linux Linux 6.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.