7.1
HIGH CVSS 3.1
CVE-2026-74507
Bluetooth: HIDP: validate numbered report payloads
Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed. KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added. The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds. Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.

INFO

Published Date :

Aug. 15, 2026, 1:17 p.m.

Last Modified :

Aug. 19, 2026, 5:21 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-74507 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Apply kernel updates to validate numbered report payloads and prevent uninitialized value use.
  • Update the Linux kernel to the latest version.
  • Apply the security patch for Bluetooth HIDP.
  • Ensure numbered report payloads are validated.
  • Reject malformed peer responses.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-74507 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-74507 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-74507 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-74507 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 19, 2026

    Action Type Old Value New Value
    Added Reference https://git.kernel.org/stable/c/011bf4350d941f1995b2bd4b815ee206cacf2b8e
    Added Reference https://git.kernel.org/stable/c/689d8bb7fee96b7196b572b015b6055c6616ce0c
    Added Reference https://git.kernel.org/stable/c/c73beb320f5705e508bf7d385b8cc5ef8d9c8b69
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '011bf4350d941f1995b2bd4b815ee206cacf2b8e', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '689d8bb7fee96b7196b572b015b6055c6616ce0c', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'c73beb320f5705e508bf7d385b8cc5ef8d9c8b69', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.265', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.216', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.183', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}]
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc6', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc6', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed. KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added. The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds. Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.
    Added Reference https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188
    Added Reference https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17
    Added Reference https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690
    Added Reference https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b
    Added Reference https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.