| 概要 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before type checks tlv_data_is_valid() reads each advertising data field length from A malformed field whose length byte is the last byte of the buffer can KASAN reported the following when a malformed MGMT_OP_ADD_ADVERTISING BUG: KASAN: vmalloc-out-of-bounds in tlv_data_is_valid() Move the existing element-length check before any type-octet inspection |
|---|---|
| 公表日 | 2026年6月25日18:16 |
| 登録日 | 2026年6月27日4:27 |
| 最終更新日 | 2026年6月25日18:16 |