CVE-2026-43017 PUBLISHED

Bluetooth: MGMT: validate mesh send advertising payload length

Assigner: Linux
Reserved: 01.05.2026 Published: 01.05.2026 Updated: 01.05.2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: MGMT: validate mesh send advertising payload length

mesh_send() currently bounds MGMT_OP_MESH_SEND by total command length, but it never verifies that the bytes supplied for the flexible adv_data[] array actually match the embedded adv_data_len field. MGMT_MESH_SEND_SIZE only covers the fixed header, so a truncated command can still pass the existing 20..50 byte range check and later drive the async mesh send path past the end of the queued command buffer.

Keep rejecting zero-length and oversized advertising payloads, but validate adv_data_len explicitly and require the command length to exactly match the flexible array size before queueing the request.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to 24fa32369cf15d8fc918bdfe94097b12e6acada0 (excl.)
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to 244b639e6a3a8e26241e201004a3a9f764476631 (excl.)
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to 0b706fb2294aff3adfd54653bda1b5e356ad4566 (excl.)
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to edb5898cfa91afe7e8f83eda18d93034c953d632 (excl.)
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to 562ed1954f0c1bff3422b7b752bd3dacf185edbf (excl.)
  • affected from b338d91703fae6f6afd67f3f75caa3b8f36ddef3 to bda93eec78cdbfe5cda00785cefebd443e56b88b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.1 is affected
  • unaffected from 0 to 6.1 (excl.)
  • unaffected from 6.1.168 to 6.1.* (incl.)
  • unaffected from 6.6.134 to 6.6.* (incl.)
  • unaffected from 6.12.81 to 6.12.* (incl.)
  • unaffected from 6.18.22 to 6.18.* (incl.)
  • unaffected from 6.19.12 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References