« Volver al listado

CVE-2026-74507

Estado: RecibidaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: HIDP: validate numbered report payloads

When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed.

KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added.

Leer descripción completaMostrar menos

The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds.

Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente) + validación insuficiente en protocolo HIDP permite envío de payloads malformados. Riesgo de ejecución arbitraria o denegación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74507",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "011bf4350d941f1995b2bd4b815ee206cacf2b8e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "689d8bb7fee96b7196b572b015b6055c6616ce0c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "c73beb320f5705e508bf7d385b8cc5ef8d9c8b69",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "b7ad105d46acd828e424454815e4cd31069e047a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "7e7162427659b70ea17cd41b1f79e2e64c246690",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "27cc0e603355c585f1e5da8398faa4d36d498188",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "9c841f59e10b5d75c398a3fc6b2da448d2a2276b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ff1731a1ae51e8e48cd559d70db536281c47f8e",
              "lessThan": "34f53d27b81a16a02828c8fdfa4e02badc326f17",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/bluetooth/hidp/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.39"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.39",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/bluetooth/hidp/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:55.733",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/011bf4350d941f1995b2bd4b815ee206cacf2b8e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/689d8bb7fee96b7196b572b015b6055c6616ce0c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c73beb320f5705e508bf7d385b8cc5ef8d9c8b69",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: HIDP: validate numbered report payloads\n\nWhen hidp_get_raw_report() waits for a numbered report,\nhidp_process_data() compares the expected report number with skb->data[0].\nA connected HIDP peer can reply with only a DATA transaction header,\nleaving the skb empty after the header is removed.\n\nKMSAN reports an uninitialized-value use in hidp_session_run(), with the\nvalue originating in __alloc_skb() through vhci_write(). The transaction\nheader checks remove the empty-frame reports, but this report remains until\nthe payload check is added.\n\nThe comparison can also consume a peer-controlled byte beyond the declared\nL2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made\nthe current code accept that byte as report ID 1 and complete\nHIDIOCGFEATURE with a zero-byte result. With this change the malformed\nresponse is rejected with -EIO, while a subsequent valid response still\nsucceeds.\n\nRequire a payload byte before comparing a numbered report ID. Unnumbered\nreports continue to accept an empty payload."
    }
  ],
  "lastModified": "2026-08-19T17:21:07.643",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}