Bluetooth: btmtk: validate WMT event SKB length before struct access
authorTristan Madani <tristan@talencesecurity.com>
Tue, 21 Apr 2026 11:14:54 +0000 (11:14 +0000)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Wed, 6 May 2026 20:22:19 +0000 (16:22 -0400)
commit634a4408c0615c523cf7531790f4f14a422b9206
treea0c3529588fea3d1f5469b501e3ae11636504b2b
parentf958c7805b18e9d69f6b322b231ecee46ec6f331
Bluetooth: btmtk: validate WMT event SKB length before struct access

btmtk_usb_hci_wmt_sync() casts the WMT event response SKB data to
struct btmtk_hci_wmt_evt (7 bytes) and struct btmtk_hci_wmt_evt_funcc
(9 bytes) without first checking that the SKB contains enough data.
A short firmware response causes out-of-bounds reads from SKB tailroom.

Use skb_pull_data() to validate and advance past the base WMT event
header. For the FUNC_CTRL case, pull the additional status field bytes
before accessing them.

Fixes: d019930b0049 ("Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
drivers/bluetooth/btmtk.c