CVE-2026-46138 | Linux Kernel up to 7.1-rc2 Bluetooth hci_le_create_big_complete_evt out-of-bounds
A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6/7.1-rc2. This affects the function hci_le_create_big_complete_evt of the component Bluetooth. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-46138. The attack requires being on the local network. There is not any exploit available.
It is suggested to upgrade the affected component.