---
id: CVE-2026-46140
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: btmtk: validate WMT event SKB length before struct access

  btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to
  struct btmtk_hci_wmt_evt (7 byte…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: btmtk: validate WMT event SKB length before struct access

  btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to
  struct btmtk_hci_wmt_evt (7 byte…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.6.142, < 6.7'
  - 'linux_kernel >= 6.11, < 6.12.88'
  - 'linux_kernel >= 6.13, < 6.18.30'
  - 'linux_kernel >= 6.19, < 7.0.7'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.7
published: '2026-05-28'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46140'
references:
  - url: 'https://git.kernel.org/stable/c/36c85f7029484d5ede769f8873d16e9c8e35533c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/624fb79dadc1b65757986a9d0fdde5c0cf3fe179'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/634a4408c0615c523cf7531790f4f14a422b9206'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/70d37a8b9229e394cc17ddad47e90b81d80fcd09'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c411cf1bfde951cfa821809cf4020ba177f76e0c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00166
epssPercentile: 0.05162
ingestedAt: '2026-07-04T12:56:09.561Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtk: validate WMT event SKB length before struct access

btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to
struct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc
(9 bytes) without first checking that the SKB contains enough data.
A short firmware response causes out-of-bounds reads from SKB tailroom.

Use skb_pull_data() to validate and advance past the base WMT event
header. For the FUNC_CTRL case, pull the additional status field bytes
before accessing them.

## Affected

- `linux_kernel >= 6.6.142, < 6.7`
- `linux_kernel >= 6.11, < 6.12.88`
- `linux_kernel >= 6.13, < 6.18.30`
- `linux_kernel >= 6.19, < 7.0.7`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.7`
