---
id: CVE-2026-98292
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct
  access


  btmtksdio.c and btmtkuart.c cast a received WMT event straight to

  struct btmtk_hci_wmt_…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct
  access


  btmtksdio.c and btmtkuart.c cast a received WMT event straight to

  struct btmtk_hci_wmt_…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e0b67035a90b58d01f911fed77b6e3da153da66e <
    5a5cfd8488c97e1b8939515429fe4c81e9f2df4f
  - >-
    Linux >= e0b67035a90b58d01f911fed77b6e3da153da66e <
    8879e3e0a84a86954c855caceead4867e74a9a27
  - Linux 5.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:19.603'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98292'
references:
  - url: 'https://git.kernel.org/stable/c/5a5cfd8488c97e1b8939515429fe4c81e9f2df4f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8879e3e0a84a86954c855caceead4867e74a9a27'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.418Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access

btmtksdio.c and btmtkuart.c cast a received WMT event straight to
struct btmtk_hci_wmt_evt and read its op/flag fields without checking
the event is long enough to contain them, unlike btmtk.c. The
FUNC_CTRL case then further casts to struct btmtk_hci_wmt_evt_funcc
and reads its 2-byte status field, again without a length check.
Firmware that sends a short or malformed WMT event makes both drivers
read past the end of the received SKB.

Mirror btmtk.c: validate the base WMT header with skb_pull_data()
before touching any of its fields, and when a FUNC_CTRL event turns
out to be the short, header-only form (a plain enable/disable ack
with no status word), decode the result from the header's own flag
byte instead (0 = success, otherwise failure).

Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
