---
id: CVE-2026-53209
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend

  Existing advertising instances can already hold the maximum extended
  advertising payload
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend

  Existing advertising instances can already hold the maximum extended
  advertising payload. When hci…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
  - CWE-131
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.1.142, < 6.1.176'
  - 'linux_kernel >= 6.6.94, < 6.6.143'
  - 'linux_kernel >= 6.12.34, < 6.12.94'
  - 'linux_kernel >= 6.15.3, < 6.16'
  - 'linux_kernel >= 6.16.1, < 6.18.36'
  - 'linux_kernel >= 6.19, < 7.0.13'
  - linux_kernel = 6.16
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.13
published: '2026-06-25'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53209'
references:
  - url: 'https://git.kernel.org/stable/c/02f50e8bb69f9b22516163a09922f5537d3b12d1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/10b0e832cc05d7aef4b92bed912cbd4a395d0862'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1338ee049a8910ba6c9cee963920e978e6893c7d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5c65b96b549ea2dcfde497436bf9e048deb87758'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cdd8bbdbee763fdf5bf343e6f7d4e79347739f62'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dafc9f57140e66a10945127aa7433c3d715dc253'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53209.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-53209'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2492762'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-53209'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53209'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026062502-CVE-2026-53209-92bf@gregkh/T
  - url: 'https://access.redhat.com/errata/RHSA-2026:65334'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67150'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00129
epssPercentile: 0.02923
ingestedAt: '2026-07-03T13:02:28.032Z'
scores:
  nvd: 7.8
  vendor: 7
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend

Existing advertising instances can already hold the maximum extended
advertising payload. When hci_adv_bcast_annoucement() prepends the
Broadcast Announcement service data to that payload, the combined data
may no longer fit in the temporary buffer used to rebuild the
advertising data.

Reject that case before copying the existing payload and report the
failure through the device log. This keeps the existing advertising
data intact and avoids overrunning the temporary buffer.

## Affected

- `linux_kernel >= 6.1.142, < 6.1.176`
- `linux_kernel >= 6.6.94, < 6.6.143`
- `linux_kernel >= 6.12.34, < 6.12.94`
- `linux_kernel >= 6.15.3, < 6.16`
- `linux_kernel >= 6.16.1, < 6.18.36`
- `linux_kernel >= 6.19, < 7.0.13`
- `linux_kernel = 6.16`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.13`

## Vendor advisories

- **RHSA-2026:65334** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10), Red Hat Enterprise Linux Real Time (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65334)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 9 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53209.json)
- **RHSA-2026:67150** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67150)
