{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255  mgmt_hci_cmd_sync() checks that the message length agrees with params_len but puts no upper bound on it. params_len is __le16 while the parameter length in the HCI command header is a u8:  \tstruct hci_command_hdr { \t\t__le16\topcode; \t\t__u8\tplen; \t} __packed;  hci_cmd_sync_alloc() assigns one to the other:  \thdr-\u003eplen = plen;  \tif (plen) \t\tskb_put_data(skb, param, plen);  so a params_len of 256 leaves plen at 0 while all 256 bytes are still appended. The frame handed to the driver then declares no parameters and carries 256 of them. On a length framed transport such as H:4 the controller takes the trailing bytes as the start of the next packet.  The mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params_len can reach about 1KB this way. Commit 03f1700b9b4d (\"Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands\") only made params_len agree with the message length, a value that fits the message but not the header field is still accepted.  Reject params_len that does not fit the header field.",
  "id": "DEBIAN-CVE-2026-80760",
  "modified": "2026-09-14T16:47:46.903395401Z",
  "published": "2026-09-04T16:18:01.070Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80760"
    }
  ],
  "upstream": [
    "CVE-2026-80760"
  ]
}