{"id":"CVE-2026-53209","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: reject oversized Broadcast Announcement prepend\n\nExisting advertising instances can already hold the maximum extended\nadvertising payload","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: reject oversized Broadcast Announcement prepend\n\nExisting advertising instances can already hold the maximum extended\nadvertising payload. When hci…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787","CWE-131"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.1.142, < 6.1.176","linux_kernel >= 6.6.94, < 6.6.143","linux_kernel >= 6.12.34, < 6.12.94","linux_kernel >= 6.15.3, < 6.16","linux_kernel >= 6.16.1, < 6.18.36","linux_kernel >= 6.19, < 7.0.13","linux_kernel = 6.16","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.13"],"published":"2026-06-25","updated":"2026-07-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53209","references":[{"url":"https://git.kernel.org/stable/c/02f50e8bb69f9b22516163a09922f5537d3b12d1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10b0e832cc05d7aef4b92bed912cbd4a395d0862","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1338ee049a8910ba6c9cee963920e978e6893c7d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c65b96b549ea2dcfde497436bf9e048deb87758","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdd8bbdbee763fdf5bf343e6f7d4e79347739f62","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dafc9f57140e66a10945127aa7433c3d715dc253","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53209.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53209"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492762"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53209"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53209"},{"url":"https://lore.kernel.org/linux-cve-announce/2026062502-CVE-2026-53209-92bf@gregkh/T"},{"url":"https://access.redhat.com/errata/RHSA-2026:65334"},{"url":"https://access.redhat.com/errata/RHSA-2026:67150"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00129,"epssPercentile":0.02944,"ingestedAt":"2026-07-03T13:02:28.032Z","scores":{"nvd":7.8,"vendor":7},"slug":"CVE-2026-53209","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: reject oversized Broadcast Announcement prepend\n\nExisting advertising instances can already hold the maximum extended\nadvertising payload. When hci_adv_bcast_annoucement() prepends the\nBroadcast Announcement service data to that payload, the combined data\nmay no longer fit in the temporary buffer used to rebuild the\nadvertising data.\n\nReject that case before copying the existing payload and report the\nfailure through the device log. This keeps the existing advertising\ndata intact and avoids overrunning the temporary buffer.\n\n## Affected\n\n- `linux_kernel >= 6.1.142, < 6.1.176`\n- `linux_kernel >= 6.6.94, < 6.6.143`\n- `linux_kernel >= 6.12.34, < 6.12.94`\n- `linux_kernel >= 6.15.3, < 6.16`\n- `linux_kernel >= 6.16.1, < 6.18.36`\n- `linux_kernel >= 6.19, < 7.0.13`\n- `linux_kernel = 6.16`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.13`\n\n## Vendor advisories\n\n- **RHSA-2026:65334** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10), Red Hat Enterprise Linux Real Time (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65334)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 9 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53209.json)\n- **RHSA-2026:67150** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67150)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}