SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89583

HIGH · CVSS 8.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Bluetooth implementation, specifically in the `eir_get_service_data()` function, which improperly handles the length of advertising data fields. This flaw can lead to an out-of-bounds read, potentially allowing an attacker to access sensitive data from adjacent memory regions. Organizations using Linux systems with Bluetooth capabilities should prioritize addressing this vulnerability to mitigate the risk of data exposure.

CVE
CVE-2026-89583
Severity
HIGH
CVSS
8.1
EPSS
0.26%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.