{"id":"AZL-106050","summary":"CVE-2026-98292 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access\n\nbtmtksdio.c and btmtkuart.c cast a received WMT event straight to\nstruct btmtk_hci_wmt_evt and read its op/flag fields without checking\nthe event is long enough to contain them, unlike btmtk.c. The\nFUNC_CTRL case then further casts to struct btmtk_hci_wmt_evt_funcc\nand reads its 2-byte status field, again without a length check.\nFirmware that sends a short or malformed WMT event makes both drivers\nread past the end of the received SKB.\n\nMirror btmtk.c: validate the base WMT header with skb_pull_data()\nbefore touching any of its fields, and when a FUNC_CTRL event turns\nout to be the short, header-only form (a plain enable/disable ack\nwith no status word), decode the result from the header's own flag\nbyte instead (0 = success, otherwise failure).\n\nVerified setup on MT7920, MT7921, MT7922 and MT7925: no regression.","modified":"2026-10-07T14:16:52.109413980Z","published":"2026-10-06T09:18:19Z","upstream":["CVE-2026-98292"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98292"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106050.json"}}],"schema_version":"1.9.0"}