216.73.217.22

CVE-2026-46140

· Published 28/05/2026 12:16 · Author: The MITRE Corporation

Labels: CVE-2026-46140 2026-05-28416baaa9-dc9f-4396-8d5f-8c081fb06d67CVE-2026-46140

Essential information

Published
28/05/2026 12:16
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.1 HIGH (v3.1)
CISA KEV
No
CWE
CWE-125
EPSS (First)
P7.2% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00175)
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS metrics

Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT event SKB length before struct access btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to struct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc (9 bytes) without first checking that the SKB contains enough data. A short firmware response causes out-of-bounds reads from SKB tailroom. Use skb_pull_data() to validate and advance past the base WMT event header. For the FUNC_CTRL case, pull the additional status field bytes before accessing them.

NVD status

NVD
View on NVD