0.0
NA
CVE-2026-74507
Bluetooth: HIDP: validate numbered report payloads
Description

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed. KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added. The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds. Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.

INFO

Published Date :

Aug. 15, 2026, 1:17 p.m.

Last Modified :

Aug. 15, 2026, 1:17 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-74507 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Apply kernel updates to validate numbered report payloads and prevent uninitialized value use.
  • Update the Linux kernel to the latest version.
  • Apply the security patch for Bluetooth HIDP.
  • Ensure numbered report payloads are validated.
  • Reject malformed peer responses.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-74507 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-74507 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-74507 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-74507 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': 'b7ad105d46acd828e424454815e4cd31069e047a', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '7e7162427659b70ea17cd41b1f79e2e64c246690', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '27cc0e603355c585f1e5da8398faa4d36d498188', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '9c841f59e10b5d75c398a3fc6b2da448d2a2276b', 'versionType': 'git'}, {'status': 'affected', 'version': '0ff1731a1ae51e8e48cd559d70db536281c47f8e', 'lessThan': '34f53d27b81a16a02828c8fdfa4e02badc326f17', 'versionType': 'git'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.39'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.39', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.151', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.103', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.44', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.8', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc6', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/bluetooth/hidp/core.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate numbered report payloads When hidp_get_raw_report() waits for a numbered report, hidp_process_data() compares the expected report number with skb->data[0]. A connected HIDP peer can reply with only a DATA transaction header, leaving the skb empty after the header is removed. KMSAN reports an uninitialized-value use in hidp_session_run(), with the value originating in __alloc_skb() through vhci_write(). The transaction header checks remove the empty-frame reports, but this report remains until the payload check is added. The comparison can also consume a peer-controlled byte beyond the declared L2CAP PDU. A DATA | FEATURE response followed by an extra 0x01 byte made the current code accept that byte as report ID 1 and complete HIDIOCGFEATURE with a zero-byte result. With this change the malformed response is rejected with -EIO, while a subsequent valid response still succeeds. Require a payload byte before comparing a numbered report ID. Unnumbered reports continue to accept an empty payload.
    Added Reference https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188
    Added Reference https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17
    Added Reference https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690
    Added Reference https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b
    Added Reference https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.