CVE-2026-74532
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate length before parsing diagnostics TLV btintel_diagnostics() accesses tlv->val[0] without first validating that the diagnostics VSE is long enough to contain that field, so may cause reading data beyond the received frame. Fix by validating the length before access.
- Published Aug 15, 2026
- Not yet scored
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available