{"id":"CVE-2026-46140","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: validate WMT event SKB length before struct access\n\nbtmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to\nstruct btmtk_hci_wmt_evt (7 byte…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: validate WMT event SKB length before struct access\n\nbtmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to\nstruct btmtk_hci_wmt_evt (7 byte…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":["CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.6.142, < 6.7","linux_kernel >= 6.11, < 6.12.88","linux_kernel >= 6.13, < 6.18.30","linux_kernel >= 6.19, < 7.0.7","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.7"],"published":"2026-05-28","updated":"2026-07-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46140","references":[{"url":"https://git.kernel.org/stable/c/36c85f7029484d5ede769f8873d16e9c8e35533c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/624fb79dadc1b65757986a9d0fdde5c0cf3fe179","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/634a4408c0615c523cf7531790f4f14a422b9206","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70d37a8b9229e394cc17ddad47e90b81d80fcd09","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c411cf1bfde951cfa821809cf4020ba177f76e0c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00131,"epssPercentile":0.03063,"ingestedAt":"2026-07-04T12:56:09.561Z","slug":"CVE-2026-46140","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: validate WMT event SKB length before struct access\n\nbtmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to\nstruct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc\n(9 bytes) without first checking that the SKB contains enough data.\nA short firmware response causes out-of-bounds reads from SKB tailroom.\n\nUse skb_pull_data() to validate and advance past the base WMT event\nheader. For the FUNC_CTRL case, pull the additional status field bytes\nbefore accessing them.\n\n## Affected\n\n- `linux_kernel >= 6.6.142, < 6.7`\n- `linux_kernel >= 6.11, < 6.12.88`\n- `linux_kernel >= 6.13, < 6.18.30`\n- `linux_kernel >= 6.19, < 7.0.7`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.7`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}