CVE-2026-53209
published 2026-06-25CVE-2026-53209: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
Existing advertising instances can already hold the maximum extended
advertising payload. When hci_adv_bcast_annoucement() prepends the
Broadcast Announcement service data to that payload, the combined data
may no longer fit in the temporary buffer used to rebuild the
advertising data.
Reject that case before copying the existing payload and report the
failure through the device log. This keeps the existing advertising
data intact and avoids overrunning the temporary buffer.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5725bc608252050ed8a4d47d59225b7dd73474c8 < dafc9f57140e66a10945127aa7433c3d715dc253 | dafc9f57140e66a10945127aa7433c3d715dc253 |
| linux | linux | >= 5725bc608252050ed8a4d47d59225b7dd73474c8 < cdd8bbdbee763fdf5bf343e6f7d4e79347739f62 | cdd8bbdbee763fdf5bf343e6f7d4e79347739f62 |
| linux | linux | >= 5725bc608252050ed8a4d47d59225b7dd73474c8 < 5c65b96b549ea2dcfde497436bf9e048deb87758 | 5c65b96b549ea2dcfde497436bf9e048deb87758 |
| linux | linux | >= 6.1.142 < 6.1.176 | 6.1.176 |
| linux | linux | >= 6.12.34 < 6.12.94 | 6.12.94 |
| linux | linux | >= 6.15.3 < 6.16 | 6.16 |
| linux | linux | >= 6.6.94 < 6.6.143 | 6.6.143 |
| linux | linux | >= 63f365eb4d1668a04070151b555d55a07ede8d4b < 10b0e832cc05d7aef4b92bed912cbd4a395d0862 | 10b0e832cc05d7aef4b92bed912cbd4a395d0862 |
| linux | linux | >= 907ef6e12fb558a0763e894311eb245a94c192dd < 02f50e8bb69f9b22516163a09922f5537d3b12d1 | 02f50e8bb69f9b22516163a09922f5537d3b12d1 |
| linux | linux | >= c621211b308816889f0a3246de448bfcef8ab3ab < 1338ee049a8910ba6c9cee963920e978e6893c7d | 1338ee049a8910ba6c9cee963920e978e6893c7d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.12 Bluetooth hci_adv_bcast_annoucement buffer overflow (Nessus ID 323563 / WID-SEC-2026-2077)
vuldb·2026-07-03·CVSS 7.8
CVE-2026-53209 [HIGH] Linux Kernel up to 7.0.12 Bluetooth hci_adv_bcast_annoucement buffer overflow (Nessus ID 323563 / WID-SEC-2026-2077)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.175/6.6.142/6.12.93/6.18.35/7.0.12. This affects the function hci_adv_bcast_annoucement of the component Bluetooth. The manipulation results in buffer overflow.
This vulnerability is reported as CVE-2026-53209. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
GHSA
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum e
ghsa_unreviewed·2026-06-25
CVE-2026-53209 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend Existing advertising instances can already hold the maximum e
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
Existing advertising instances can already hold the maximum extended
advertising payload. When hci_adv_bcast_annoucement() prepends the
Broadcast Announcement service data to that payload, the combined data
may no longer fit in the temporary buffer used to rebuild the
advertising data.
Reject that case before copying the existing payload and report the
failure through the device log. This keeps the existing advertising
data intact and avoids overrunning the temporary buffer.
Red Hat
kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53209 [MEDIUM] CWE-131 kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
Existing advertising instances can already hold the maximum extended
advertising payload. When hci_adv_bcast_annoucement() prepends the
Broadcast Announcement service data to that payload, the combined data
may no longer fit in the temporary buffer used to rebuild the
advertising data.
Reject that case before copying the existing payload and report the
failure through the device log. This keeps the existing advertising
data intact and avoids overrunning the temporary buffer.
A flaw was found in the Bluetooth subsystem of the Linux kernel, specifically within the `hci_sync` comp
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/02f50e8bb69f9b22516163a09922f5537d3b12d1https://git.kernel.org/stable/c/10b0e832cc05d7aef4b92bed912cbd4a395d0862https://git.kernel.org/stable/c/1338ee049a8910ba6c9cee963920e978e6893c7dhttps://git.kernel.org/stable/c/5c65b96b549ea2dcfde497436bf9e048deb87758https://git.kernel.org/stable/c/cdd8bbdbee763fdf5bf343e6f7d4e79347739f62https://git.kernel.org/stable/c/dafc9f57140e66a10945127aa7433c3d715dc253
2026-06-25
Published