Skip to finding
important · Bluetooth — Linux HIDP

A connected Bluetooth HID peer can make Linux read beyond a zero-length frame.

Affects

Linux kernel Bluetooth HIDP support for Classic Bluetooth input devices.

With an established HIDP session, an attacker can send an empty interrupt or control frame whose absent first byte is nevertheless accessed by the kernel.

Detail and 1 source

We do not know whether that read produces an observable disclosure, a reliable crash or a stronger effect, and a released fixed version is not yet established.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026