{"id":"CVE-2026-97907","summary":"Bluetooth: btrtl: Don't leak return code when parsing firmware format v2","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btrtl: Don't leak return code when parsing firmware format v2\n\nWhen key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally\nignores all security headers. However, the implementation simply breaks\nfrom a switch statement and leaks uninitialized return code `rc' (if the\nfirst section is a security one) or the previous section's `rc'.\n\nFix it by really skipping a loop with `continue'. For consistency and\nreadability, also do the same for the default case.","modified":"2026-09-26T03:48:30.755925135Z","published":"2026-09-25T10:22:32.244Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97907.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/422f6547259654bae690713614c794dd1e2c0a0b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/83e3e515fd261600ed8491fb0a8bcdfb115c904e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/90f3a142b5f8596a565b8e080d18a8050be6edef"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c4249cf6e80b1bd62a6a409aaabe760fe025dac3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97907.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97907"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"9a24ce5e29b15c4c6b0c89c04f9df6ce14addefa"},{"fixed":"90f3a142b5f8596a565b8e080d18a8050be6edef"},{"fixed":"422f6547259654bae690713614c794dd1e2c0a0b"},{"fixed":"c4249cf6e80b1bd62a6a409aaabe760fe025dac3"},{"fixed":"83e3e515fd261600ed8491fb0a8bcdfb115c904e"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97907.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"fixed":"6.12.111"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.53"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97907.json"}}],"schema_version":"1.9.0"}